Search
2,803 CVEs · Low severity
CVEs (2,803, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 2,803 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2025-15674 | LOW | Patched | 2.7 | 2026-08-06 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through … |
| CVE-2026-19046 | LOW | 3.3 | 2026-08-06 | A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesS… | |
| CVE-2026-15599 | LOW | Patched | 3.3 | 2026-08-06 | Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain… |
| CVE-2025-14779 | LOW | Patched | 3.8 | 2026-08-06 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce or… |
| CVE-2025-13736 | LOW | Patched | 3.7 | 2026-08-06 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays thei… |
| CVE-2025-12627 | LOW | Patched | 2.4 | 2026-08-06 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained … |
| CVE-2026-18839 | LOW | 2.2 | 2026-08-05 | An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to … | |
| CVE-2026-70437 | LOW | 3.7 | 2026-08-05 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and exp… | |
| CVE-2026-70430 | LOW | 2.7 | 2026-08-05 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, all… | |
| CVE-2026-70600 | LOW | Patched | 3.1 | 2026-08-05 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autof… |
| CVE-2026-70598 | LOW | Patched | 3.9 | 2026-08-05 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rende… |
| CVE-2026-12730 | LOW | 3.8 | 2026-08-05 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 … | |
| CVE-2026-8029 | LOW | 3.9 | 2026-08-05 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database … | |
| CVE-2026-16993 | LOW | Patched | 3.7 | 2026-08-05 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying… |
| CVE-2026-16746 | LOW | Patched | 2.7 | 2026-08-05 | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-… |
| CVE-2025-15677 | LOW | Patched | 3.5 | 2026-08-05 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege … |
| CVE-2026-18852 | LOW | 3.3 | 2026-08-05 | A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the fi… | |
| CVE-2026-18817 | LOW | 2.2 | 2026-08-04 | A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api… | |
| CVE-2026-70483 | LOW | Patched | 3.1 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks … |
| CVE-2026-16791 | LOW | 3.9 | 2026-08-04 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o… | |
| CVE-2026-18790 | LOW | 3.3 | 2026-08-04 | A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/fr… | |
| CVE-2026-16070 | LOW | Patched | 2.7 | 2026-08-04 | The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request p… |
| CVE-2026-16068 | LOW | Patched | 3.5 | 2026-08-04 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it… |
| CVE-2026-11366 | LOW | Patched | 3.7 | 2026-08-04 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres… |
| CVE-2026-68744 | LOW | 3.3 | 2026-08-04 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh… |