Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,803 CVEs · Low severity

CVEs (2,803, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 2,803 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-55824 LOW Patched 2.6 2026-07-31 Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries t…
CVE-2026-25552 LOW Patched 3.7 2026-07-31 Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-…
CVE-2026-56571 LOW 3.7 2026-07-31 HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network…
CVE-2026-56570 LOW 3.7 2026-07-31 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Accou…
CVE-2026-56568 LOW 3.7 2026-07-31 HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error mess…
CVE-2026-18217 LOW 3.4 2026-07-31 A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authen…
CVE-2026-18209 LOW 3.4 2026-07-31 A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check desig…
CVE-2026-18206 LOW 3.7 2026-07-31 A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a …
CVE-2026-15381 LOW Patched 3.7 2026-07-31 The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform …
CVE-2026-14927 LOW Patched 3.7 2026-07-31 The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed o…
CVE-2026-14862 LOW Patched 3.7 2026-07-31 The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the s…
CVE-2026-14849 LOW Patched 3.7 2026-07-31 The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads dir…
CVE-2026-13393 LOW Patched 3.5 2026-07-31 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on…
CVE-2026-58039 LOW 3.3 2026-07-31 A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact …
CVE-2026-41709 LOW 2.7 2026-07-30 VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
CVE-2026-59326 LOW 3.3 2026-07-30 The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound H…
CVE-2026-15054 LOW Patched 3.7 2026-07-30 The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to subm…
CVE-2026-14222 LOW Patched 3.8 2026-07-30 The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contribu…
CVE-2026-14221 LOW 3.8 2026-07-30 The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any aut…
CVE-2026-14188 LOW Patched 2.7 2026-07-30 The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticat…
CVE-2026-18011 LOW Patched 2.4 2026-07-30 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from proc…
CVE-2026-18000 LOW Patched 3.1 2026-07-30 Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-o…
CVE-2026-17997 LOW Patched 3.1 2026-07-30 Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin da…
CVE-2026-17984 LOW Patched 3.3 2026-07-30 Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chro…
CVE-2026-17980 LOW Patched 3.1 2026-07-30 Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to le…