Search
15,629 CVEs · Low severity
CVEs (15,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 15,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2025-15614 | LOW | Patched | 3.3 | 2026-09-05 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … |
| CVE-2026-84927 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contri… |
| CVE-2026-84926 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user… |
| CVE-2026-84745 | LOW | Patched | 2.7 | 2026-09-05 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with … |
| CVE-2026-84225 | LOW | Patched | 2.2 | 2026-09-05 | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administr… |
| CVE-2026-81348 | LOW | Patched | 3.7 | 2026-09-05 | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticat… |
| CVE-2026-78150 | LOW | Patched | 2.7 | 2026-09-05 | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges … |
| CVE-2025-15694 | LOW | Patched | 3.5 | 2026-09-05 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p… |
| CVE-2025-15693 | LOW | Patched | 2.7 | 2026-09-05 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,… |
| CVE-2026-86141 | LOW | Patched | 2.9 | 2026-09-05 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. |
| CVE-2026-86137 | LOW | Patched | 2.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. |
| CVE-2026-85704 | LOW | 3.7 | 2026-09-04 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s… | |
| CVE-2026-18540 | LOW | Patched | 3.7 | 2026-09-04 | undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original re… |
| CVE-2026-85008 | LOW | Patched | 3.7 | 2026-09-04 | undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of sa… |
| CVE-2026-84947 | LOW | Patched | 3.7 | 2026-09-04 | undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the inte… |
| CVE-2026-18858 | LOW | 3.3 | 2026-09-04 | IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. | |
| CVE-2026-85592 | LOW | Patched | 3.7 | 2026-09-04 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call… |
| CVE-2026-84066 | LOW | Patched | 3.1 | 2026-09-04 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified … |
| CVE-2026-85406 | LOW | 3.5 | 2026-09-04 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to c… | |
| CVE-2026-85405 | LOW | 3.5 | 2026-09-04 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument … | |
| CVE-2026-85207 | LOW | 3.5 | 2026-09-03 | A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation… | |
| CVE-2026-85052 | LOW | 3.1 | 2026-09-03 | Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the s… | |
| CVE-2026-49456 | LOW | Patched | 3.1 | 2026-09-03 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.… |
| CVE-2026-84969 | LOW | 3.7 | 2026-09-03 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field i… | |
| CVE-2026-85030 | LOW | 3.7 | 2026-09-03 | A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/rou… |