Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

405 CVEs · Low severity

CVEs (405)

Showing 151–175 of 405

CVE ID Severity Patch CVSS Published Description
CVE-2026-81715 LOW Patched 3.3 2026-08-27 openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the -&hellip;
CVE-2026-81696 LOW Patched 3.3 2026-08-27 openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files contain&hellip;
CVE-2026-81695 LOW Patched 3.3 2026-08-27 openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files &hellip;
CVE-2026-81694 LOW Patched 3.3 2026-08-27 openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing the&hellip;
CVE-2026-81685 LOW Patched 3.3 2026-08-27 openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into t&hellip;
CVE-2026-81102 LOW 3.1 2026-08-27 The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mod&hellip;
CVE-2025-62343 LOW 3.1 2026-08-27 HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
CVE-2026-13416 LOW Patched 3.5 2026-08-27 The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (whe&hellip;
CVE-2026-21807 LOW 3.9 2026-08-26 HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
CVE-2025-62341 LOW 3.7 2026-08-26 HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in ce&hellip;
CVE-2026-21809 LOW 3.9 2026-08-26 HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an atta&hellip;
CVE-2026-77573 LOW Patched 3.5 2026-08-26 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository U&hellip;
CVE-2026-77508 LOW Patched 3.5 2026-08-26 Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{usernam&hellip;
CVE-2026-56547 LOW 3.5 2026-08-26 The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embed&hellip;
CVE-2026-47843 LOW Patched 3.7 2026-08-26 In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. React&hellip;
CVE-2026-54548 LOW Patched 3.3 2026-08-26 kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no user&hellip;
CVE-2026-13480 LOW Patched 3.1 2026-08-26 The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes withou&hellip;
CVE-2026-13479 LOW Patched 3.1 2026-08-26 The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only &hellip;
CVE-2026-7487 LOW Patched 3.5 2026-08-26 GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an au&hellip;
CVE-2026-19220 LOW Patched 3.7 2026-08-26 The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticate&hellip;
CVE-2026-9805 LOW 2.7 2026-08-26 SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
CVE-2026-80201 LOW Patched 2.0 2026-08-26 Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attack&hellip;
CVE-2026-80199 LOW Patched 3.7 2026-08-26 Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. &hellip;
CVE-2026-79289 LOW Patched 3.1 2026-08-25 Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to&hellip;
CVE-2026-79272 LOW Patched 3.1 2026-08-25 Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data&hellip;