Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 15,635 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81715 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the -… |
| CVE-2026-81694 | LOW | Patched | 3.3 | 2026-08-27 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing the… |
| CVE-2026-81695 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files … |
| CVE-2026-81696 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files contain… |
| CVE-2026-81685 | LOW | Patched | 3.3 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into t… |
| CVE-2026-81102 | LOW | 3.1 | 2026-08-27 | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mod… | |
| CVE-2025-62343 | LOW | 3.1 | 2026-08-27 | HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion. | |
| CVE-2026-13416 | LOW | Patched | 3.5 | 2026-08-27 | The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (whe… |
| CVE-2026-21807 | LOW | 3.9 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | |
| CVE-2025-62341 | LOW | 3.7 | 2026-08-26 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in ce… | |
| CVE-2026-21809 | LOW | 3.9 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an atta… | |
| CVE-2026-77573 | LOW | Patched | 3.5 | 2026-08-26 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository U… |
| CVE-2026-77508 | LOW | Patched | 3.5 | 2026-08-26 | Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{usernam… |
| CVE-2026-56547 | LOW | 3.5 | 2026-08-26 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embed… | |
| CVE-2026-47843 | LOW | Patched | 3.7 | 2026-08-26 | In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. React… |
| CVE-2026-54548 | LOW | Patched | 3.3 | 2026-08-26 | kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no user… |
| CVE-2026-13479 | LOW | Patched | 3.1 | 2026-08-26 | The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only … |
| CVE-2026-13480 | LOW | Patched | 3.1 | 2026-08-26 | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes withou… |
| CVE-2026-7487 | LOW | Patched | 3.5 | 2026-08-26 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an au… |
| CVE-2026-19220 | LOW | Patched | 3.7 | 2026-08-26 | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticate… |
| CVE-2026-9805 | LOW | 2.7 | 2026-08-26 | SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow. | |
| CVE-2026-80199 | LOW | Patched | 3.7 | 2026-08-26 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. … |
| CVE-2026-80201 | LOW | Patched | 2.0 | 2026-08-26 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attack… |
| CVE-2026-79289 | LOW | Patched | 3.1 | 2026-08-25 | Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to… |
| CVE-2026-79272 | LOW | Patched | 3.1 | 2026-08-25 | Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data… |