Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 15,095 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-61865 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. |
| CVE-2026-61864 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. |
| CVE-2026-61863 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small … |
| CVE-2026-61862 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is n… |
| CVE-2026-61860 | LOW | Patched | 3.7 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to … |
| CVE-2026-61859 | LOW | Patched | 3.3 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows… |
| CVE-2026-61464 | LOW | Patched | 1.8 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which ca… |
| CVE-2026-56764 | LOW | Patched | 3.7 | 2026-07-15 | Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual fun… |
| CVE-2026-56375 | LOW | 3.3 | 2026-07-15 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources… | |
| CVE-2026-42447 | LOW | Patched | 3.6 | 2026-07-14 | jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java appends arches and per… |
| CVE-2026-21840 | LOW | 3.1 | 2026-07-14 | HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform s… | |
| CVE-2026-48329 | LOW | 2.7 | 2026-07-14 | ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vu… | |
| CVE-2026-48001 | LOW | Patched | 3.7 | 2026-07-14 | Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond t… |
| CVE-2026-15642 | LOW | Patched | 3.3 | 2026-07-14 | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with a… |
| CVE-2026-15058 | LOW | Patched | 3.1 | 2026-07-14 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages vi… |
| CVE-2026-50419 | LOW | Patched | 3.3 | 2026-07-14 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. |
| CVE-2026-50416 | LOW | Patched | 3.3 | 2026-07-14 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |
| CVE-2026-52841 | LOW | 3.1 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `p… | |
| CVE-2026-52840 | LOW | 2.7 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the reque… | |
| CVE-2026-52839 | LOW | 3.3 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, provi… | |
| CVE-2026-52838 | LOW | 2.6 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking set… | |
| CVE-2025-62826 | LOW | Patched | 3.1 | 2026-07-14 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, Fort… |
| CVE-2025-62675 | LOW | Patched | 3.4 | 2026-07-14 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, Fort… |
| CVE-2026-15690 | LOW | 3.1 | 2026-07-14 | A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of th… | |
| CVE-2026-15678 | LOW | 3.5 | 2026-07-14 | A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads… |