Search
15,090 CVEs · Low severity
EOL hidden · Show all products
CVEs (15,090, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 15,090 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-16218 | LOW | 2.6 | 2026-07-19 | A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of the file app/workers/tasks/storage.py of the component… | |
| CVE-2026-16213 | LOW | 3.3 | 2026-07-19 | A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/… | |
| CVE-2026-16211 | LOW | 2.6 | 2026-07-19 | A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ral… | |
| CVE-2026-16207 | LOW | 3.7 | 2026-07-19 | A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results… | |
| CVE-2026-16205 | LOW | 2.4 | 2026-07-19 | A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php o… | |
| CVE-2026-16203 | LOW | 3.5 | 2026-07-19 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such m… | |
| CVE-2026-16202 | LOW | 3.5 | 2026-07-19 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. Thi… | |
| CVE-2026-16156 | LOW | 3.5 | 2026-07-18 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the … | |
| CVE-2026-16155 | LOW | 3.5 | 2026-07-18 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The … | |
| CVE-2026-54335 | LOW | Patched | 3.7 | 2026-07-17 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exporte… |
| CVE-2026-54244 | LOW | Patched | 3.5 | 2026-07-17 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Cont… |
| CVE-2026-7364 | LOW | 3.1 | 2026-07-17 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Sec… | |
| CVE-2026-14971 | LOW | 3.9 | 2026-07-17 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized oper… | |
| CVE-2026-16073 | LOW | 3.5 | 2026-07-17 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function Star.text_to_image/NetworkRenderStrategy.render of th… | |
| CVE-2025-59866 | LOW | 3.3 | 2026-07-17 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in… | |
| CVE-2026-21764 | LOW | 3.1 | 2026-07-17 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behav… | |
| CVE-2026-21762 | LOW | 3.7 | 2026-07-17 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking,… | |
| CVE-2024-23573 | LOW | 3.7 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.… | |
| CVE-2024-32389 | LOW | 3.5 | 2026-07-16 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update UR… | |
| CVE-2026-62994 | LOW | Patched | 3.7 | 2026-07-16 | CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configur… |
| CVE-2026-47088 | LOW | 3.1 | 2026-07-16 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email … | |
| CVE-2026-47087 | LOW | 3.5 | 2026-07-16 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access … | |
| CVE-2026-47086 | LOW | 3.5 | 2026-07-16 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GE… | |
| CVE-2026-47081 | LOW | 3.1 | 2026-07-16 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could… | |
| CVE-2026-44970 | LOW | Patched | 3.1 | 2026-07-16 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py seria… |