Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81846 | LOW | Patched | 3.5 | 2026-09-01 | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through Us… |
| CVE-2026-81836 | LOW | 3.7 | 2026-08-28 | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component… | |
| CVE-2026-81725 | LOW | Patched | 3.7 | 2026-08-27 | NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying… |
| CVE-2026-81723 | LOW | Patched | 3.7 | 2026-08-27 | NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB blo… |
| CVE-2026-81717 | LOW | Patched | 3.5 | 2026-08-27 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untru… |
| CVE-2026-81715 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the -… |
| CVE-2026-81696 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files contain… |
| CVE-2026-81695 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files … |
| CVE-2026-81694 | LOW | Patched | 3.3 | 2026-08-27 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing the… |
| CVE-2026-81685 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into t… |
| CVE-2026-8136 | LOW | 2.4 | 2026-05-08 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of… | |
| CVE-2026-81348 | LOW | Patched | 3.7 | 2026-09-05 | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticat… |
| CVE-2026-8124 | LOW | Patched | 3.3 | 2026-05-08 | A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads t… |
| CVE-2026-81200 | LOW | Patched | 2.7 | 2026-08-29 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to … |
| CVE-2026-81198 | LOW | Patched | 3.8 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u… |
| CVE-2026-81196 | LOW | Patched | 2.7 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access … |
| CVE-2026-8119 | LOW | Patched | 3.3 | 2026-05-08 | A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Perf… |
| CVE-2026-81168 | LOW | 3.7 | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Pa… | |
| CVE-2026-81161 | LOW | 3.3 | 2026-09-02 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notificati… | |
| CVE-2026-81159 | LOW | 3.7 | 2026-09-02 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. | |
| CVE-2026-81102 | LOW | 3.1 | 2026-08-27 | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mod… | |
| CVE-2026-8088 | LOW | Patched | 3.3 | 2026-05-07 | A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipul… |
| CVE-2026-8084 | LOW | Patched | 3.3 | 2026-05-07 | A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-… |
| CVE-2026-8074 | LOW | Patched | 3.8 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager wit… |
| CVE-2026-8029 | LOW | 3.9 | 2026-08-05 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database … |