Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-18739 LOW 2.5 2026-08-04 A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through …
CVE-2026-68744 LOW 3.3 2026-08-04 A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh…
CVE-2026-58044 LOW 3.7 2026-08-04 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he…
CVE-2026-18682 LOW 3.1 2026-08-03 A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipu…
CVE-2026-56608 LOW 3.7 2026-08-03 HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view admini…
CVE-2026-63545 LOW 2.4 2026-08-03 Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
CVE-2026-18591 LOW 2.1 2026-08-03 A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.mees…
CVE-2026-16274 LOW Patched 2.7 2026-08-03 The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with …
CVE-2026-16276 LOW Patched 2.7 2026-08-03 The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users wit…
CVE-2026-15231 LOW Patched 2.7 2026-08-03 The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and retur…
CVE-2026-18581 LOW 3.3 2026-08-03 A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinj…
CVE-2026-10774 LOW Patched 2.4 2026-08-02 Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the P…
CVE-2026-15939 LOW Patched 2.7 2026-08-02 The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there …
CVE-2026-67334 LOW Patched 3.8 2026-08-01 better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeS…
CVE-2026-67319 LOW Patched 3.7 2026-08-01 axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already b…
CVE-2026-66401 LOW Patched 2.1 2026-08-01 FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the…
CVE-2026-14823 LOW Patched 2.2 2026-08-01 The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-l…
CVE-2026-14195 LOW Patched 2.7 2026-08-01 The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor rol…
CVE-2026-14197 LOW Patched 3.8 2026-08-01 The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to …
CVE-2026-14214 LOW Patched 2.7 2026-08-01 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user w…
CVE-2026-10827 LOW Patched 3.5 2026-08-01 The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end…
CVE-2026-11882 LOW Patched 3.7 2026-08-01 The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenti…
CVE-2026-54787 LOW Patched 3.1 2026-07-31 sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an E…
CVE-2026-55825 LOW 3.1 2026-07-31 Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segm…
CVE-2026-55824 LOW Patched 2.6 2026-07-31 Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries t…