Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9377 LOW 2.4 2026-05-24 A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation o…
CVE-2026-9373 LOW 3.7 2026-05-24 A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulatio…
CVE-2026-9370 LOW 3.7 2026-05-24 A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file j…
CVE-2026-9357 LOW 3.5 2026-05-24 A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting. It is possib…
CVE-2026-9306 LOW 3.7 2026-05-23 A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router…
CVE-2026-9269 LOW Patched 3.5 2026-06-12 The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use…
CVE-2026-9249 LOW Patched 3.1 2026-05-22 Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. T…
CVE-2026-9248 LOW Patched 2.6 2026-05-22 Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachment…
CVE-2026-9247 LOW Patched 2.4 2026-05-22 Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the …
CVE-2026-9143 LOW Patched 3.7 2026-06-19 There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen.  This may silently discard high bits if a siz…
CVE-2026-9088 LOW 2.7 2026-06-05 A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the g…
CVE-2026-9062 LOW Patched 3.4 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read …
CVE-2026-9061 LOW Patched 3.5 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2026-9060 LOW Patched 3.5 2026-06-10 The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2026-8981 LOW Patched 3.5 2026-06-09 The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fi…
CVE-2026-8823 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad&hellip;
CVE-2026-8803 LOW 3.7 2026-05-18 A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee L&hellip;
CVE-2026-8801 LOW Patched 3.5 2026-07-08 Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
CVE-2026-8800 LOW Patched 2.7 2026-07-08 Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-8770 LOW Patched 3.3 2026-05-18 A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON&hellip;
CVE-2026-8741 LOW Patched 3.1 2026-05-17 A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH&hellip;
CVE-2026-8662 LOW Patched 3.3 2026-06-25 Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file &hellip;
CVE-2026-8651 LOW Patched 3.7 2026-07-08 Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 befo&hellip;
CVE-2026-8579 LOW Patched 3.1 2026-05-14 Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an&hellip;
CVE-2026-8578 LOW Patched 3.1 2026-05-14 Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via&hellip;