Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-81846 LOW Patched 3.5 2026-09-01 An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through Us…
CVE-2026-81836 LOW 3.7 2026-08-28 A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component…
CVE-2026-81725 LOW Patched 3.7 2026-08-27 NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying…
CVE-2026-81723 LOW Patched 3.7 2026-08-27 NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB blo…
CVE-2026-81717 LOW Patched 3.5 2026-08-27 openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untru…
CVE-2026-81715 LOW Patched 3.3 2026-08-27 openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the -&hellip;
CVE-2026-81696 LOW Patched 3.3 2026-08-27 openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files contain&hellip;
CVE-2026-81695 LOW Patched 3.3 2026-08-27 openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files &hellip;
CVE-2026-81694 LOW Patched 3.3 2026-08-27 openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing the&hellip;
CVE-2026-81685 LOW Patched 3.3 2026-08-27 openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into t&hellip;
CVE-2026-8136 LOW 2.4 2026-05-08 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of&hellip;
CVE-2026-81348 LOW Patched 3.7 2026-09-05 The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticat&hellip;
CVE-2026-8124 LOW Patched 3.3 2026-05-08 A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads t&hellip;
CVE-2026-81200 LOW Patched 2.7 2026-08-29 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to &hellip;
CVE-2026-81198 LOW Patched 3.8 2026-09-02 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u&hellip;
CVE-2026-81196 LOW Patched 2.7 2026-09-02 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access &hellip;
CVE-2026-8119 LOW Patched 3.3 2026-05-08 A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Perf&hellip;
CVE-2026-81168 LOW 3.7 2026-09-02 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Pa&hellip;
CVE-2026-81161 LOW 3.3 2026-09-02 Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notificati&hellip;
CVE-2026-81159 LOW 3.7 2026-09-02 Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
CVE-2026-81102 LOW 3.1 2026-08-27 The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mod&hellip;
CVE-2026-8088 LOW Patched 3.3 2026-05-07 A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipul&hellip;
CVE-2026-8084 LOW Patched 3.3 2026-05-07 A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-&hellip;
CVE-2026-8074 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager wit&hellip;
CVE-2026-8029 LOW 3.9 2026-08-05 The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database &hellip;