Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,629 CVEs · Low severity

CVEs (15,629, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 15,629 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85022 LOW 3.5 2026-09-03 A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/comp…
CVE-2026-84653 LOW 3.5 2026-09-02 Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page…
CVE-2026-63020 LOW 3.1 2026-09-02 A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages  Impact: An attacker may trick authenti…
CVE-2026-78600 LOW Patched 3.5 2026-09-02 Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after …
CVE-2026-78587 LOW Patched 3.1 2026-09-02 Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctl…
CVE-2026-19698 LOW Patched 3.5 2026-09-02 The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, a…
CVE-2026-14326 LOW 3.8 2026-09-02 The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol…
CVE-2025-15692 LOW Patched 3.5 2026-09-02 The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users…
CVE-2023-3360 LOW Patched 3.3 2026-09-02 The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use…
CVE-2026-81168 LOW 3.7 2026-09-02 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Pa…
CVE-2026-81161 LOW 3.3 2026-09-02 Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notificati…
CVE-2026-81159 LOW 3.7 2026-09-02 Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
CVE-2026-81198 LOW Patched 3.8 2026-09-02 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u…
CVE-2026-81196 LOW Patched 2.7 2026-09-02 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access …
CVE-2026-77787 LOW Patched 2.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object iden…
CVE-2026-77785 LOW Patched 2.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning …
CVE-2026-77784 LOW Patched 2.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allow…
CVE-2026-77783 LOW Patched 3.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated vis…
CVE-2026-84438 LOW 3.5 2026-09-02 A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W…
CVE-2026-84437 LOW 3.5 2026-09-02 A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc…
CVE-2026-84359 LOW Patched 3.1 2026-09-02 Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted …
CVE-2026-84355 LOW Patched 3.1 2026-09-02 Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy…
CVE-2026-84331 LOW Patched 3.1 2026-09-02 Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via …
CVE-2026-84328 LOW Patched 3.1 2026-09-02 Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v…
CVE-2026-84368 LOW Patched 3.7 2026-09-01 joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi pac…