Search
972 CVEs · Low severity
CVEs (972, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 972 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85022 | LOW | 3.5 | 2026-09-03 | A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/comp… | |
| CVE-2026-84653 | LOW | 3.5 | 2026-09-02 | Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page… | |
| CVE-2026-63020 | LOW | 3.1 | 2026-09-02 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenti… | |
| CVE-2026-78600 | LOW | Patched | 3.5 | 2026-09-02 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after … |
| CVE-2026-78587 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctl… |
| CVE-2026-19698 | LOW | Patched | 3.5 | 2026-09-02 | The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, a… |
| CVE-2026-14326 | LOW | 3.8 | 2026-09-02 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol… | |
| CVE-2025-15692 | LOW | Patched | 3.5 | 2026-09-02 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users… |
| CVE-2023-3360 | LOW | Patched | 3.3 | 2026-09-02 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use… |
| CVE-2026-81168 | LOW | 3.7 | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Pa… | |
| CVE-2026-81161 | LOW | 3.3 | 2026-09-02 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notificati… | |
| CVE-2026-81159 | LOW | 3.7 | 2026-09-02 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. | |
| CVE-2026-81198 | LOW | Patched | 3.8 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u… |
| CVE-2026-81196 | LOW | Patched | 2.7 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access … |
| CVE-2026-77787 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object iden… |
| CVE-2026-77785 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning … |
| CVE-2026-77784 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allow… |
| CVE-2026-77783 | LOW | Patched | 3.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated vis… |
| CVE-2026-84438 | LOW | 3.5 | 2026-09-02 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W… | |
| CVE-2026-84437 | LOW | 3.5 | 2026-09-02 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc… | |
| CVE-2026-84359 | LOW | Patched | 3.1 | 2026-09-02 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted … |
| CVE-2026-84355 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy… |
| CVE-2026-84331 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via … |
| CVE-2026-84328 | LOW | Patched | 3.1 | 2026-09-02 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v… |
| CVE-2026-84368 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi pac… |