Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8028 LOW Patched 3.7 2026-05-06 A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of t…
CVE-2026-8026 LOW Patched 3.7 2026-05-06 A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts…
CVE-2026-8022 LOW Patched 3.1 2026-05-06 Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross…
CVE-2026-80201 LOW Patched 2.0 2026-08-26 Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attack…
CVE-2026-80199 LOW Patched 3.7 2026-08-26 Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. …
CVE-2026-8017 LOW Patched 3.1 2026-05-06 Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium sec…
CVE-2026-79783 LOW Patched 3.6 2026-08-25 rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on…
CVE-2026-79782 LOW Patched 3.1 2026-08-25 rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintex…
CVE-2026-79777 LOW 2.7 2026-08-25 rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, …
CVE-2026-7968 LOW Patched 3.1 2026-05-06 Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same…
CVE-2026-7966 LOW Patched 3.1 2026-05-06 Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to by…
CVE-2026-7965 LOW Patched 3.1 2026-05-06 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cr…
CVE-2026-79615 LOW Patched 2.7 2026-08-28 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allow…
CVE-2026-7959 LOW Patched 3.1 2026-05-06 Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolati…
CVE-2026-7954 LOW Patched 3.1 2026-05-06 Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HT…
CVE-2026-7949 LOW Patched 3.1 2026-05-06 Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte…
CVE-2026-7945 LOW Patched 3.1 2026-05-06 Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site…
CVE-2026-7944 LOW Patched 3.1 2026-05-06 Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to…
CVE-2026-7937 LOW Patched 3.1 2026-05-06 Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navi…
CVE-2026-79289 LOW Patched 3.1 2026-08-25 Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to…
CVE-2026-79272 LOW Patched 3.1 2026-08-25 Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data…
CVE-2026-79255 LOW Patched 3.1 2026-08-25 Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v…
CVE-2026-79228 LOW Patched 3.1 2026-08-25 Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation…
CVE-2026-79203 LOW Patched 3.1 2026-08-25 Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation vi…
CVE-2026-79191 LOW Patched 3.1 2026-08-25 Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social eng…