Search
2,585 CVEs · Low severity
CVEs (2,585, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 2,585 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-12482 | LOW | 3.1 | 2026-07-14 | A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/uti… | |
| CVE-2026-44753 | LOW | 3.7 | 2026-07-14 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration o… | |
| CVE-2026-15605 | LOW | 3.1 | 2026-07-13 | A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the com… | |
| CVE-2026-15594 | LOW | 3.7 | 2026-07-13 | A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media … | |
| CVE-2026-9820 | LOW | Patched | 3.8 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager rol… |
| CVE-2026-61971 | LOW | 2.7 | 2026-07-13 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access C… | |
| CVE-2026-15532 | LOW | 2.4 | 2026-07-13 | A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such mani… | |
| CVE-2026-15528 | LOW | 3.3 | 2026-07-13 | A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manip… | |
| CVE-2026-15526 | LOW | 3.3 | 2026-07-13 | A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component sc… | |
| CVE-2026-15524 | LOW | 3.3 | 2026-07-13 | A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Su… | |
| CVE-2026-15505 | LOW | 3.5 | 2026-07-12 | A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmat… | |
| CVE-2026-10668 | LOW | Patched | 2.4 | 2026-07-12 | The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsu… |
| CVE-2026-61874 | LOW | Patched | 3.1 | 2026-07-12 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shar… |
| CVE-2026-56281 | LOW | Patched | 3.8 | 2026-07-12 | Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request bo… |
| CVE-2026-15493 | LOW | 3.5 | 2026-07-12 | A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file … | |
| CVE-2026-61870 | LOW | Patched | 2.9 | 2026-07-11 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing s… |
| CVE-2026-61861 | LOW | Patched | 3.7 | 2026-07-11 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation … |
| CVE-2026-61858 | LOW | Patched | 3.3 | 2026-07-11 | ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to… |
| CVE-2026-61857 | LOW | Patched | 3.7 | 2026-07-11 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files w… |
| CVE-2026-61465 | LOW | Patched | 3.3 | 2026-07-11 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a cr… |
| CVE-2026-56372 | LOW | Patched | 3.3 | 2026-07-11 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magni… |
| CVE-2026-55807 | LOW | Patched | 3.1 | 2026-07-10 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, f… |
| CVE-2026-13235 | LOW | Patched | 3.3 | 2026-07-10 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to… |
| CVE-2026-13233 | LOW | 3.3 | 2026-07-10 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.… | |
| CVE-2026-13232 | LOW | 3.1 | 2026-07-10 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka a… |