Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 15,095 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9377 | LOW | 2.4 | 2026-05-24 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation o… | |
| CVE-2026-9373 | LOW | 3.7 | 2026-05-24 | A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulatio… | |
| CVE-2026-9370 | LOW | 3.7 | 2026-05-24 | A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file j… | |
| CVE-2026-9357 | LOW | 3.5 | 2026-05-24 | A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting. It is possib… | |
| CVE-2026-9306 | LOW | 3.7 | 2026-05-23 | A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router… | |
| CVE-2026-9269 | LOW | Patched | 3.5 | 2026-06-12 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use… |
| CVE-2026-9249 | LOW | Patched | 3.1 | 2026-05-22 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. T… |
| CVE-2026-9248 | LOW | Patched | 2.6 | 2026-05-22 | Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachment… |
| CVE-2026-9247 | LOW | Patched | 2.4 | 2026-05-22 | Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the … |
| CVE-2026-9143 | LOW | Patched | 3.7 | 2026-06-19 | There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a siz… |
| CVE-2026-9088 | LOW | 2.7 | 2026-06-05 | A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the g… | |
| CVE-2026-9062 | LOW | Patched | 3.4 | 2026-06-13 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read … |
| CVE-2026-9061 | LOW | Patched | 3.5 | 2026-06-13 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-9060 | LOW | Patched | 3.5 | 2026-06-10 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-8981 | LOW | Patched | 3.5 | 2026-06-09 | The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fi… |
| CVE-2026-8823 | LOW | Patched | 3.8 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad… |
| CVE-2026-8803 | LOW | 3.7 | 2026-05-18 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee L… | |
| CVE-2026-8801 | LOW | Patched | 3.5 | 2026-07-08 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. |
| CVE-2026-8800 | LOW | Patched | 2.7 | 2026-07-08 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| CVE-2026-8770 | LOW | Patched | 3.3 | 2026-05-18 | A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON… |
| CVE-2026-8741 | LOW | Patched | 3.1 | 2026-05-17 | A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH… |
| CVE-2026-8662 | LOW | Patched | 3.3 | 2026-06-25 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file … |
| CVE-2026-8651 | LOW | Patched | 3.7 | 2026-07-08 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 befo… |
| CVE-2026-8579 | LOW | Patched | 3.1 | 2026-05-14 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an… |
| CVE-2026-8578 | LOW | Patched | 3.1 | 2026-05-14 | Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via… |