Search
399 CVEs · Low severity
CVEs (399)
Showing 101–125 of 399
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-82622 | LOW | 3.5 | 2026-08-31 | A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of … | |
| CVE-2026-82596 | LOW | 3.3 | 2026-08-31 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUti… | |
| CVE-2026-82555 | LOW | 3.7 | 2026-08-30 | A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the … | |
| CVE-2026-82656 | LOW | Patched | 2.6 | 2026-08-30 | Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path travers… |
| CVE-2026-82488 | LOW | 3.5 | 2026-08-30 | A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument User… | |
| CVE-2026-82483 | LOW | 3.5 | 2026-08-30 | A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden … | |
| CVE-2026-82482 | LOW | 3.5 | 2026-08-30 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the comp… | |
| CVE-2026-78364 | LOW | Patched | 3.5 | 2026-08-30 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allo… |
| CVE-2026-82562 | LOW | Patched | 3.7 | 2026-08-30 | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into… |
| CVE-2026-81200 | LOW | Patched | 2.7 | 2026-08-29 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to … |
| CVE-2026-77704 | LOW | Patched | 2.7 | 2026-08-29 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appoi… |
| CVE-2026-55785 | LOW | Patched | 3.7 | 2026-08-28 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/proces… |
| CVE-2026-77063 | LOW | Patched | 3.7 | 2026-08-28 | multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition i… |
| CVE-2026-13735 | LOW | 3.7 | 2026-08-28 | Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_message(), any type-4 transport-data message whos… | |
| CVE-2026-82112 | LOW | 3.5 | 2026-08-28 | A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executin… | |
| CVE-2026-38093 | LOW | 3.3 | 2026-08-28 | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream(… | |
| CVE-2026-82249 | LOW | Patched | 3.1 | 2026-08-28 | gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns t… |
| CVE-2026-82238 | LOW | 3.1 | 2026-08-28 | filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending conc… | |
| CVE-2026-82237 | LOW | 3.1 | 2026-08-28 | filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it sur… | |
| CVE-2026-82236 | LOW | 3.1 | 2026-08-28 | File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the su… | |
| CVE-2026-52681 | LOW | Patched | 3.1 | 2026-08-28 | Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Com… |
| CVE-2026-42393 | LOW | Patched | 3.1 | 2026-08-28 | The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same ne… |
| CVE-2026-40204 | LOW | 3.1 | 2026-08-28 | None None None No publicly available exploits are known. | |
| CVE-2026-40203 | LOW | Patched | 3.7 | 2026-08-28 | When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail… |
| CVE-2026-79615 | LOW | Patched | 2.7 | 2026-08-28 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allow… |