Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48524 LOW Patched 3.7 2026-05-28 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an un…
CVE-2026-4835 LOW 3.5 2026-03-26 A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component…
CVE-2026-4833 LOW 3.3 2026-03-26 A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipul…
CVE-2026-48329 LOW 2.7 2026-07-14 ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vu…
CVE-2026-4831 LOW 3.7 2026-03-26 A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the …
CVE-2026-48289 LOW Patched 3.5 2026-06-09 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by…
CVE-2026-48288 LOW Patched 3.5 2026-06-09 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by…
CVE-2026-4823 LOW 2.5 2026-03-25 A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a m…
CVE-2026-48191 LOW Patched 3.5 2026-06-01 An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about num…
CVE-2026-48190 LOW Patched 3.5 2026-06-01 An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Plea…
CVE-2026-48156 LOW Patched 3.3 2026-05-28 pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This require…
CVE-2026-48102 LOW Patched 3.1 2026-06-05 7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File …
CVE-2026-48011 LOW 3.7 2026-06-10 Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timin…
CVE-2026-48001 LOW Patched 3.7 2026-07-14 Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond t…
CVE-2026-47782 LOW 3.3 2026-05-20 Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a …
CVE-2026-47716 LOW Patched 3.1 2026-05-26 Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the re…
CVE-2026-47715 LOW Patched 3.1 2026-05-26 Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up tha…
CVE-2026-47713 LOW Patched 2.0 2026-05-28 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token…
CVE-2026-47712 LOW Patched 3.3 2026-06-10 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=…
CVE-2026-47337 LOW 3.3 2026-05-28 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered…
CVE-2026-47336 LOW 3.3 2026-05-28 Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an …
CVE-2026-47330 LOW 3.3 2026-05-28 Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug c…
CVE-2026-47329 LOW 3.3 2026-05-28 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by a…
CVE-2026-47327 LOW 3.3 2026-05-28 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unpr…
CVE-2026-47275 LOW 2.6 2026-07-20 In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5…