Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

978 CVEs · Low severity

CVEs (978, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 978 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-15674 LOW Patched 2.7 2026-08-06 The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through …
CVE-2026-19046 LOW 3.3 2026-08-06 A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesS…
CVE-2026-15599 LOW Patched 3.3 2026-08-06 Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain…
CVE-2025-14779 LOW Patched 3.8 2026-08-06 The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce or…
CVE-2025-13736 LOW Patched 3.7 2026-08-06 When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays thei…
CVE-2025-12627 LOW Patched 2.4 2026-08-06 The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained …
CVE-2026-18839 LOW 2.2 2026-08-05 An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to …
CVE-2026-70437 LOW 3.7 2026-08-05 Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and exp…
CVE-2026-70430 LOW 2.7 2026-08-05 Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, all…
CVE-2026-70600 LOW Patched 3.1 2026-08-05 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autof…
CVE-2026-70598 LOW Patched 3.9 2026-08-05 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rende…
CVE-2026-12730 LOW 3.8 2026-08-05 IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 …
CVE-2026-8029 LOW 3.9 2026-08-05 The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database …
CVE-2026-16993 LOW Patched 3.7 2026-08-05 The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying…
CVE-2026-16746 LOW Patched 2.7 2026-08-05 The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-…
CVE-2025-15677 LOW Patched 3.5 2026-08-05 The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege …
CVE-2026-18852 LOW 3.3 2026-08-05 A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the fi…
CVE-2026-18817 LOW 2.2 2026-08-04 A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api…
CVE-2026-70483 LOW Patched 3.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks …
CVE-2026-16791 LOW 3.9 2026-08-04 A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o…
CVE-2026-18790 LOW 3.3 2026-08-04 A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/fr…
CVE-2026-16070 LOW Patched 2.7 2026-08-04 The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request p…
CVE-2026-16068 LOW Patched 3.5 2026-08-04 The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it…
CVE-2026-11366 LOW Patched 3.7 2026-08-04 The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres…
CVE-2026-68744 LOW 3.3 2026-08-04 A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh…