Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 15,095 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-44969 | LOW | Patched | 2.5 | 2026-07-16 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at… |
| CVE-2026-35145 | LOW | Patched | 3.1 | 2026-07-16 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) … |
| CVE-2026-35143 | LOW | Patched | 3.0 | 2026-07-16 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authen… |
| CVE-2026-35142 | LOW | Patched | 2.6 | 2026-07-16 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses,… |
| CVE-2026-35141 | LOW | Patched | 2.6 | 2026-07-16 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authenti… |
| CVE-2026-35140 | LOW | Patched | 3.0 | 2026-07-16 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session c… |
| CVE-2026-12907 | LOW | Patched | 2.7 | 2026-07-16 | The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to cre… |
| CVE-2026-12906 | LOW | Patched | 2.7 | 2026-07-16 | The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing u… |
| CVE-2026-38755 | LOW | 2.9 | 2026-07-15 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-38752 | LOW | 2.9 | 2026-07-15 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | |
| CVE-2026-15921 | LOW | 3.1 | 2026-07-15 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other command… | |
| CVE-2026-55398 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tun… |
| CVE-2026-33444 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol… |
| CVE-2026-40958 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can crea… |
| CVE-2026-40956 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel … |
| CVE-2026-40955 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total… |
| CVE-2026-40954 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total… |
| CVE-2026-62683 | LOW | Patched | 3.1 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can … |
| CVE-2026-60065 | LOW | 3.7 | 2026-07-15 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send reques… | |
| CVE-2026-61872 | LOW | Patched | 2.5 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry para… |
| CVE-2026-61871 | LOW | Patched | 3.7 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that trigger… |
| CVE-2026-61869 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead… |
| CVE-2026-61868 | LOW | Patched | 3.7 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to… |
| CVE-2026-61867 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF ima… |
| CVE-2026-61866 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malform… |