Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8568 | LOW | Patched | 3.1 | 2026-05-14 | Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation v… |
| CVE-2026-85592 | LOW | Patched | 3.7 | 2026-09-04 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call… |
| CVE-2026-8556 | LOW | Patched | 3.1 | 2026-05-14 | Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-o… |
| CVE-2026-8554 | LOW | Patched | 3.1 | 2026-05-14 | Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds m… |
| CVE-2026-8553 | LOW | Patched | 3.1 | 2026-05-14 | Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write v… |
| CVE-2026-8545 | LOW | Patched | 3.1 | 2026-05-14 | Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a… |
| CVE-2026-85406 | LOW | 3.5 | 2026-09-04 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to c… | |
| CVE-2026-85405 | LOW | 3.5 | 2026-09-04 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument … | |
| CVE-2026-8536 | LOW | Patched | 3.1 | 2026-05-14 | Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process… |
| CVE-2026-85207 | LOW | 3.5 | 2026-09-03 | A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation… | |
| CVE-2026-85052 | LOW | 3.1 | 2026-09-03 | Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the s… | |
| CVE-2026-85030 | LOW | 3.7 | 2026-09-03 | A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/rou… | |
| CVE-2026-85022 | LOW | 3.5 | 2026-09-03 | A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/comp… | |
| CVE-2026-85008 | LOW | Patched | 3.7 | 2026-09-04 | undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of sa… |
| CVE-2026-84969 | LOW | 3.7 | 2026-09-03 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field i… | |
| CVE-2026-84947 | LOW | Patched | 3.7 | 2026-09-04 | undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the inte… |
| CVE-2026-84927 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contri… |
| CVE-2026-84926 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user… |
| CVE-2026-8492 | LOW | Patched | 2.7 | 2026-05-19 | Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drup… |
| CVE-2026-8491 | LOW | Patched | 3.7 | 2026-05-19 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from… |
| CVE-2026-8477 | LOW | Patched | 2.7 | 2026-05-22 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed e… |
| CVE-2026-84745 | LOW | Patched | 2.7 | 2026-09-05 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with … |
| CVE-2026-84653 | LOW | 3.5 | 2026-09-02 | Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page… | |
| CVE-2026-84438 | LOW | 3.5 | 2026-09-02 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W… | |
| CVE-2026-84437 | LOW | 3.5 | 2026-09-02 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc… |