Search
2,803 CVEs · Low severity
CVEs (2,803, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 2,803 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-55824 | LOW | Patched | 2.6 | 2026-07-31 | Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries t… |
| CVE-2026-25552 | LOW | Patched | 3.7 | 2026-07-31 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-… |
| CVE-2026-56571 | LOW | 3.7 | 2026-07-31 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network… | |
| CVE-2026-56570 | LOW | 3.7 | 2026-07-31 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Accou… | |
| CVE-2026-56568 | LOW | 3.7 | 2026-07-31 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error mess… | |
| CVE-2026-18217 | LOW | 3.4 | 2026-07-31 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authen… | |
| CVE-2026-18209 | LOW | 3.4 | 2026-07-31 | A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check desig… | |
| CVE-2026-18206 | LOW | 3.7 | 2026-07-31 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a … | |
| CVE-2026-15381 | LOW | Patched | 3.7 | 2026-07-31 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform … |
| CVE-2026-14927 | LOW | Patched | 3.7 | 2026-07-31 | The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed o… |
| CVE-2026-14862 | LOW | Patched | 3.7 | 2026-07-31 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the s… |
| CVE-2026-14849 | LOW | Patched | 3.7 | 2026-07-31 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads dir… |
| CVE-2026-13393 | LOW | Patched | 3.5 | 2026-07-31 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on… |
| CVE-2026-58039 | LOW | 3.3 | 2026-07-31 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact … | |
| CVE-2026-41709 | LOW | 2.7 | 2026-07-30 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. | |
| CVE-2026-59326 | LOW | 3.3 | 2026-07-30 | The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound H… | |
| CVE-2026-15054 | LOW | Patched | 3.7 | 2026-07-30 | The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to subm… |
| CVE-2026-14222 | LOW | Patched | 3.8 | 2026-07-30 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contribu… |
| CVE-2026-14221 | LOW | 3.8 | 2026-07-30 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any aut… | |
| CVE-2026-14188 | LOW | Patched | 2.7 | 2026-07-30 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticat… |
| CVE-2026-18011 | LOW | Patched | 2.4 | 2026-07-30 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from proc… |
| CVE-2026-18000 | LOW | Patched | 3.1 | 2026-07-30 | Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-o… |
| CVE-2026-17997 | LOW | Patched | 3.1 | 2026-07-30 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin da… |
| CVE-2026-17984 | LOW | Patched | 3.3 | 2026-07-30 | Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chro… |
| CVE-2026-17980 | LOW | Patched | 3.1 | 2026-07-30 | Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to le… |