Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

399 CVEs · Low severity

CVEs (399)

Showing 101–125 of 399

CVE ID Severity Patch CVSS Published Description
CVE-2026-82622 LOW 3.5 2026-08-31 A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of …
CVE-2026-82596 LOW 3.3 2026-08-31 A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUti…
CVE-2026-82555 LOW 3.7 2026-08-30 A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the …
CVE-2026-82656 LOW Patched 2.6 2026-08-30 Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path travers…
CVE-2026-82488 LOW 3.5 2026-08-30 A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument User…
CVE-2026-82483 LOW 3.5 2026-08-30 A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden …
CVE-2026-82482 LOW 3.5 2026-08-30 A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the comp…
CVE-2026-78364 LOW Patched 3.5 2026-08-30 The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allo…
CVE-2026-82562 LOW Patched 3.7 2026-08-30 ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into…
CVE-2026-81200 LOW Patched 2.7 2026-08-29 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to …
CVE-2026-77704 LOW Patched 2.7 2026-08-29 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appoi…
CVE-2026-55785 LOW Patched 3.7 2026-08-28 free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/proces…
CVE-2026-77063 LOW Patched 3.7 2026-08-28 multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition i…
CVE-2026-13735 LOW 3.7 2026-08-28 Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_message(), any type-4 transport-data message whos…
CVE-2026-82112 LOW 3.5 2026-08-28 A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executin…
CVE-2026-38093 LOW 3.3 2026-08-28 file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream(…
CVE-2026-82249 LOW Patched 3.1 2026-08-28 gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns t…
CVE-2026-82238 LOW 3.1 2026-08-28 filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending conc…
CVE-2026-82237 LOW 3.1 2026-08-28 filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it sur…
CVE-2026-82236 LOW 3.1 2026-08-28 File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the su…
CVE-2026-52681 LOW Patched 3.1 2026-08-28 Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Com…
CVE-2026-42393 LOW Patched 3.1 2026-08-28 The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same ne…
CVE-2026-40204 LOW 3.1 2026-08-28 None None None No publicly available exploits are known.
CVE-2026-40203 LOW Patched 3.7 2026-08-28 When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail…
CVE-2026-79615 LOW Patched 2.7 2026-08-28 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allow…