Search
15,090 CVEs · Low severity
EOL hidden · Show all products
CVEs (15,090, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 15,090 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-12017 | LOW | Patched | 3.1 | 2026-06-11 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolat… |
| CVE-2026-53809 | LOW | Patched | 3.8 | 2026-06-11 | OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of… |
| CVE-2026-44489 | LOW | Patched | 3.7 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still const… |
| CVE-2026-11956 | LOW | 3.7 | 2026-06-11 | A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Ex… | |
| CVE-2026-9694 | LOW | Patched | 2.6 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, … |
| CVE-2026-6976 | LOW | Patched | 3.7 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions c… |
| CVE-2026-3553 | LOW | Patched | 3.1 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions c… |
| CVE-2026-41000 | LOW | 3.7 | 2026-06-11 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay o… | |
| CVE-2026-47712 | LOW | Patched | 3.3 | 2026-06-10 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=… |
| CVE-2026-48011 | LOW | 3.7 | 2026-06-10 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timin… | |
| CVE-2026-45380 | LOW | Patched | 3.6 | 2026-06-10 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, a one-byte off-by-one error in SafeOutPathBui… |
| CVE-2022-48575 | LOW | Patched | 3.5 | 2026-06-10 | A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4. |
| CVE-2026-50568 | LOW | Patched | 3.6 | 2026-06-10 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Sanit… |
| CVE-2026-49497 | LOW | Patched | 3.3 | 2026-06-10 | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before const… |
| CVE-2024-58350 | LOW | Patched | 2.9 | 2026-06-10 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and … |
| CVE-2026-9060 | LOW | Patched | 3.5 | 2026-06-10 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-41694 | LOW | Patched | 3.7 | 2026-06-10 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able… |
| CVE-2026-48289 | LOW | Patched | 3.5 | 2026-06-09 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by… |
| CVE-2026-48288 | LOW | Patched | 3.5 | 2026-06-09 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by… |
| CVE-2026-45642 | LOW | Patched | 3.9 | 2026-06-09 | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. |
| CVE-2026-45485 | LOW | Patched | 3.3 | 2026-06-09 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45466 | LOW | 3.3 | 2026-06-09 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-45459 | LOW | 3.3 | 2026-06-09 | Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2026-45455 | LOW | 3.3 | 2026-06-09 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-42770 | LOW | Patched | 3.7 | 2026-06-09 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A m… |