Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8028 | LOW | Patched | 3.7 | 2026-05-06 | A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of t… |
| CVE-2026-8026 | LOW | Patched | 3.7 | 2026-05-06 | A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts… |
| CVE-2026-8022 | LOW | Patched | 3.1 | 2026-05-06 | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross… |
| CVE-2026-80201 | LOW | Patched | 2.0 | 2026-08-26 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attack… |
| CVE-2026-80199 | LOW | Patched | 3.7 | 2026-08-26 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. … |
| CVE-2026-8017 | LOW | Patched | 3.1 | 2026-05-06 | Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium sec… |
| CVE-2026-79783 | LOW | Patched | 3.6 | 2026-08-25 | rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on… |
| CVE-2026-79782 | LOW | Patched | 3.1 | 2026-08-25 | rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintex… |
| CVE-2026-79777 | LOW | 2.7 | 2026-08-25 | rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, … | |
| CVE-2026-7968 | LOW | Patched | 3.1 | 2026-05-06 | Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same… |
| CVE-2026-7966 | LOW | Patched | 3.1 | 2026-05-06 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to by… |
| CVE-2026-7965 | LOW | Patched | 3.1 | 2026-05-06 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cr… |
| CVE-2026-79615 | LOW | Patched | 2.7 | 2026-08-28 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allow… |
| CVE-2026-7959 | LOW | Patched | 3.1 | 2026-05-06 | Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolati… |
| CVE-2026-7954 | LOW | Patched | 3.1 | 2026-05-06 | Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HT… |
| CVE-2026-7949 | LOW | Patched | 3.1 | 2026-05-06 | Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte… |
| CVE-2026-7945 | LOW | Patched | 3.1 | 2026-05-06 | Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site… |
| CVE-2026-7944 | LOW | Patched | 3.1 | 2026-05-06 | Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to… |
| CVE-2026-7937 | LOW | Patched | 3.1 | 2026-05-06 | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navi… |
| CVE-2026-79289 | LOW | Patched | 3.1 | 2026-08-25 | Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to… |
| CVE-2026-79272 | LOW | Patched | 3.1 | 2026-08-25 | Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data… |
| CVE-2026-79255 | LOW | Patched | 3.1 | 2026-08-25 | Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v… |
| CVE-2026-79228 | LOW | Patched | 3.1 | 2026-08-25 | Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation… |
| CVE-2026-79203 | LOW | Patched | 3.1 | 2026-08-25 | Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation vi… |
| CVE-2026-79191 | LOW | Patched | 3.1 | 2026-08-25 | Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social eng… |