Search
15,629 CVEs · Low severity
CVEs (15,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 15,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18839 | LOW | 2.2 | 2026-08-05 | An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to … | |
| CVE-2026-70437 | LOW | 3.7 | 2026-08-05 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and exp… | |
| CVE-2026-70430 | LOW | 2.7 | 2026-08-05 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, all… | |
| CVE-2026-70600 | LOW | Patched | 3.1 | 2026-08-05 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autof… |
| CVE-2026-70598 | LOW | Patched | 3.9 | 2026-08-05 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rende… |
| CVE-2026-12730 | LOW | 3.8 | 2026-08-05 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 … | |
| CVE-2026-8029 | LOW | 3.9 | 2026-08-05 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database … | |
| CVE-2026-16993 | LOW | Patched | 3.7 | 2026-08-05 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying… |
| CVE-2026-16746 | LOW | Patched | 2.7 | 2026-08-05 | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-… |
| CVE-2025-15677 | LOW | Patched | 3.5 | 2026-08-05 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege … |
| CVE-2026-18852 | LOW | 3.3 | 2026-08-05 | A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the fi… | |
| CVE-2026-18817 | LOW | 2.2 | 2026-08-04 | A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api… | |
| CVE-2026-70483 | LOW | Patched | 3.1 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks … |
| CVE-2026-16791 | LOW | 3.9 | 2026-08-04 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o… | |
| CVE-2026-18790 | LOW | 3.3 | 2026-08-04 | A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/fr… | |
| CVE-2026-16070 | LOW | Patched | 2.7 | 2026-08-04 | The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request p… |
| CVE-2026-16068 | LOW | Patched | 3.5 | 2026-08-04 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it… |
| CVE-2026-11366 | LOW | Patched | 3.7 | 2026-08-04 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres… |
| CVE-2026-68744 | LOW | 3.3 | 2026-08-04 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh… | |
| CVE-2026-18739 | LOW | 2.5 | 2026-08-04 | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through … | |
| CVE-2026-18569 | LOW | 3.7 | 2026-08-04 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authenticatio… | |
| CVE-2026-58044 | LOW | 3.7 | 2026-08-04 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2026-18682 | LOW | 3.1 | 2026-08-03 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipu… | |
| CVE-2026-56608 | LOW | 3.7 | 2026-08-03 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view admini… | |
| CVE-2026-63545 | LOW | 2.4 | 2026-08-03 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users. |