Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86227 LOW 3.1 2026-09-06 A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argu…
CVE-2026-86226 LOW 3.5 2026-09-06 A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipula…
CVE-2021-48006 LOW Patched 3.3 2026-09-06 PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on…
CVE-2026-86181 LOW 3.5 2026-09-06 A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the c…
CVE-2025-15614 LOW Patched 3.3 2026-09-05 ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files …
CVE-2026-84926 LOW Patched 2.7 2026-09-05 The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user…
CVE-2026-84927 LOW Patched 2.7 2026-09-05 The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contri…
CVE-2026-84225 LOW Patched 2.2 2026-09-05 The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administr…
CVE-2026-84745 LOW Patched 2.7 2026-09-05 The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with …
CVE-2026-78150 LOW Patched 2.7 2026-09-05 The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges …
CVE-2026-81348 LOW Patched 3.7 2026-09-05 The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticat…
CVE-2025-15693 LOW Patched 2.7 2026-09-05 The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,…
CVE-2025-15694 LOW Patched 3.5 2026-09-05 The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p…
CVE-2026-86141 LOW Patched 2.9 2026-09-05 xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
CVE-2026-86137 LOW Patched 2.9 2026-09-05 In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
CVE-2026-85704 LOW 3.7 2026-09-04 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s…
CVE-2026-18540 LOW Patched 3.7 2026-09-04 undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original re…
CVE-2026-84947 LOW Patched 3.7 2026-09-04 undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the inte…
CVE-2026-85008 LOW Patched 3.7 2026-09-04 undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of sa…
CVE-2026-18858 LOW 3.3 2026-09-04 IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
CVE-2026-85592 LOW Patched 3.7 2026-09-04 phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call…
CVE-2026-84066 LOW Patched 3.1 2026-09-04 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified …
CVE-2026-85405 LOW 3.5 2026-09-04 A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument …
CVE-2026-85406 LOW 3.5 2026-09-04 A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to c…
CVE-2026-45197 LOW 2.5 2026-09-04 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised G…