Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1784 | LOW | 3.9 | 2024-02-23 | A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulatio… | |
| CVE-2024-24758 | LOW | Patched | 3.9 | 2024-02-16 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authenticat… |
| CVE-2023-45718 | LOW | Patched | 3.9 | 2024-02-09 | Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happ… |
| CVE-2023-41782 | LOW | Patched | 3.9 | 2024-01-05 | There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to … |
| CVE-2023-6690 | LOW | Patched | 3.9 | 2023-12-21 | A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository … |
| CVE-2023-32726 | LOW | Patched | 3.9 | 2023-12-18 | The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server. |
| CVE-2023-49284 | LOW | Patched | 3.9 | 2023-12-05 | fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certain Unicode non-characters internally for marking wil… |
| CVE-2023-48231 | LOW | Patched | 3.9 | 2023-11-16 | Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application ha… |
| CVE-2023-48232 | LOW | Patched | 3.9 | 2023-11-16 | Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and… |
| CVE-2023-38411 | LOW | Patched | 3.9 | 2023-11-14 | Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escalation of privilege via l… |
| CVE-2023-46126 | LOW | Patched | 3.9 | 2023-10-25 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, helping enforce privacy regulations in c… |
| CVE-2023-46122 | LOW | Patched | 3.9 | 2023-10-23 | sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would have potential to overwr… |
| CVE-2023-45143 | LOW | Patched | 3.9 | 2023-10-12 | Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization headers on cross-origin redirects, but did not … |
| CVE-2023-36555 | LOW | Patched | 3.9 | 2023-10-10 | An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or comman… |
| CVE-2023-4753 | LOW | Patched | 3.9 | 2023-09-21 | OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input. |
| CVE-2023-5084 | LOW | Patched | 3.9 | 2023-09-20 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. |
| CVE-2023-40732 | LOW | Patched | 3.9 | 2023-09-12 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on lo… |
| CVE-2023-41329 | LOW | Patched | 3.9 | 2023-09-06 | WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying t… |
| CVE-2023-0654 | LOW | Patched | 3.9 | 2023-08-29 | Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application a… |
| CVE-2023-0238 | LOW | Patched | 3.9 | 2023-08-29 | Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app installed on a victim's de… |
| CVE-2023-3800 | LOW | 3.9 | 2023-07-20 | A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function of the file /admin/index/index.html#/admin/mall.good… | |
| CVE-2023-3363 | LOW | Patched | 3.9 | 2023-07-13 | An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to … |
| CVE-2023-20867 | LOW | Patched | 3.9 | 2023-06-13 | A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. |
| CVE-2023-28829 | LOW | Patched | 3.9 | 2023-06-13 | A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PC… |
| CVE-2023-30571 | LOW | Patched | 3.9 | 2023-05-29 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process… |