Search
15,629 CVEs · Low severity
CVEs (15,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 15,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18591 | LOW | 2.1 | 2026-08-03 | A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.mees… | |
| CVE-2026-16276 | LOW | Patched | 2.7 | 2026-08-03 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users wit… |
| CVE-2026-16274 | LOW | Patched | 2.7 | 2026-08-03 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with … |
| CVE-2026-15231 | LOW | Patched | 2.7 | 2026-08-03 | The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and retur… |
| CVE-2026-18581 | LOW | 3.3 | 2026-08-03 | A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinj… | |
| CVE-2026-10774 | LOW | Patched | 2.4 | 2026-08-02 | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the P… |
| CVE-2026-15939 | LOW | Patched | 2.7 | 2026-08-02 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there … |
| CVE-2026-67334 | LOW | Patched | 3.8 | 2026-08-01 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeS… |
| CVE-2026-67319 | LOW | Patched | 3.7 | 2026-08-01 | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already b… |
| CVE-2026-66401 | LOW | Patched | 2.1 | 2026-08-01 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the… |
| CVE-2026-14823 | LOW | Patched | 2.2 | 2026-08-01 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-l… |
| CVE-2026-14214 | LOW | Patched | 2.7 | 2026-08-01 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user w… |
| CVE-2026-14197 | LOW | Patched | 3.8 | 2026-08-01 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to … |
| CVE-2026-14195 | LOW | Patched | 2.7 | 2026-08-01 | The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor rol… |
| CVE-2026-11882 | LOW | Patched | 3.7 | 2026-08-01 | The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenti… |
| CVE-2026-10827 | LOW | Patched | 3.5 | 2026-08-01 | The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end… |
| CVE-2026-54787 | LOW | Patched | 3.1 | 2026-07-31 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an E… |
| CVE-2026-55825 | LOW | 3.1 | 2026-07-31 | Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segm… | |
| CVE-2026-57232 | LOW | Patched | 3.1 | 2026-07-31 | Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderC… |
| CVE-2026-55824 | LOW | Patched | 2.6 | 2026-07-31 | Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries t… |
| CVE-2026-25552 | LOW | Patched | 3.7 | 2026-07-31 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-… |
| CVE-2026-56571 | LOW | 3.7 | 2026-07-31 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network… | |
| CVE-2026-56570 | LOW | 3.7 | 2026-07-31 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Accou… | |
| CVE-2026-56568 | LOW | 3.7 | 2026-07-31 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error mess… | |
| CVE-2026-18217 | LOW | 3.4 | 2026-07-31 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authen… |