Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84368 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi pac… |
| CVE-2026-84367 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used… |
| CVE-2026-84359 | LOW | Patched | 3.1 | 2026-09-02 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted … |
| CVE-2026-84355 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy… |
| CVE-2026-84331 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via … |
| CVE-2026-84328 | LOW | Patched | 3.1 | 2026-09-02 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v… |
| CVE-2026-84307 | LOW | Patched | 3.7 | 2026-09-01 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents … |
| CVE-2026-84225 | LOW | Patched | 2.2 | 2026-09-05 | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administr… |
| CVE-2026-84066 | LOW | Patched | 3.1 | 2026-09-04 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified … |
| CVE-2026-8404 | LOW | Patched | 3.1 | 2026-06-03 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response … |
| CVE-2026-8387 | LOW | Patched | 2.4 | 2026-07-01 | A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()`… |
| CVE-2026-82906 | LOW | 3.7 | 2026-08-31 | A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component… | |
| CVE-2026-82863 | LOW | Patched | 3.3 | 2026-08-31 | @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify… |
| CVE-2026-82810 | LOW | 3.3 | 2026-08-31 | A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListe… | |
| CVE-2026-8276 | LOW | 3.7 | 2026-05-11 | A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file modules/mysql_server/mysql_server.go of the component MySQ… | |
| CVE-2026-8275 | LOW | 3.7 | 2026-05-11 | A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBody of the file modules/zerogod/zerogod_ipp_primitives… | |
| CVE-2026-82699 | LOW | 2.7 | 2026-08-31 | A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the com… | |
| CVE-2026-82697 | LOW | 3.7 | 2026-08-31 | A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function sessi… | |
| CVE-2026-82677 | LOW | 2.4 | 2026-08-31 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This… | |
| CVE-2026-82671 | LOW | 3.4 | 2026-08-31 | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_… | |
| CVE-2026-82665 | LOW | 3.8 | 2026-08-31 | A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController… | |
| CVE-2026-82656 | LOW | Patched | 2.6 | 2026-08-30 | Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path travers… |
| CVE-2026-82631 | LOW | 2.2 | 2026-08-31 | A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blo… | |
| CVE-2026-82622 | LOW | 3.5 | 2026-08-31 | A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of … | |
| CVE-2026-8262 | LOW | 2.4 | 2026-05-11 | A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross si… |