Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8568 LOW Patched 3.1 2026-05-14 Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation v…
CVE-2026-85592 LOW Patched 3.7 2026-09-04 phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call…
CVE-2026-8556 LOW Patched 3.1 2026-05-14 Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-o…
CVE-2026-8554 LOW Patched 3.1 2026-05-14 Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds m…
CVE-2026-8553 LOW Patched 3.1 2026-05-14 Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write v…
CVE-2026-8545 LOW Patched 3.1 2026-05-14 Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a…
CVE-2026-85406 LOW 3.5 2026-09-04 A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to c…
CVE-2026-85405 LOW 3.5 2026-09-04 A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument …
CVE-2026-8536 LOW Patched 3.1 2026-05-14 Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process…
CVE-2026-85207 LOW 3.5 2026-09-03 A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation…
CVE-2026-85052 LOW 3.1 2026-09-03 Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the s…
CVE-2026-85030 LOW 3.7 2026-09-03 A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/rou…
CVE-2026-85022 LOW 3.5 2026-09-03 A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/comp…
CVE-2026-85008 LOW Patched 3.7 2026-09-04 undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of sa…
CVE-2026-84969 LOW 3.7 2026-09-03 A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field i…
CVE-2026-84947 LOW Patched 3.7 2026-09-04 undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the inte…
CVE-2026-84927 LOW Patched 2.7 2026-09-05 The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contri…
CVE-2026-84926 LOW Patched 2.7 2026-09-05 The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user…
CVE-2026-8492 LOW Patched 2.7 2026-05-19 Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drup…
CVE-2026-8491 LOW Patched 3.7 2026-05-19 Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from…
CVE-2026-8477 LOW Patched 2.7 2026-05-22 Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed e…
CVE-2026-84745 LOW Patched 2.7 2026-09-05 The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with …
CVE-2026-84653 LOW 3.5 2026-09-02 Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page…
CVE-2026-84438 LOW 3.5 2026-09-02 A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W…
CVE-2026-84437 LOW 3.5 2026-09-02 A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc…