Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,585 CVEs · Low severity

CVEs (2,585, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 2,585 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-12482 LOW 3.1 2026-07-14 A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/uti…
CVE-2026-44753 LOW 3.7 2026-07-14 SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration o…
CVE-2026-15605 LOW 3.1 2026-07-13 A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the com…
CVE-2026-15594 LOW 3.7 2026-07-13 A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media …
CVE-2026-9820 LOW Patched 3.8 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager rol&hellip;
CVE-2026-61971 LOW 2.7 2026-07-13 Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access C&hellip;
CVE-2026-15532 LOW 2.4 2026-07-13 A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such mani&hellip;
CVE-2026-15528 LOW 3.3 2026-07-13 A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manip&hellip;
CVE-2026-15526 LOW 3.3 2026-07-13 A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component sc&hellip;
CVE-2026-15524 LOW 3.3 2026-07-13 A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Su&hellip;
CVE-2026-15505 LOW 3.5 2026-07-12 A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmat&hellip;
CVE-2026-10668 LOW Patched 2.4 2026-07-12 The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsu&hellip;
CVE-2026-61874 LOW Patched 3.1 2026-07-12 filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shar&hellip;
CVE-2026-56281 LOW Patched 3.8 2026-07-12 Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request bo&hellip;
CVE-2026-15493 LOW 3.5 2026-07-12 A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file &hellip;
CVE-2026-61870 LOW Patched 2.9 2026-07-11 ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing s&hellip;
CVE-2026-61861 LOW Patched 3.7 2026-07-11 ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation &hellip;
CVE-2026-61858 LOW Patched 3.3 2026-07-11 ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to&hellip;
CVE-2026-61857 LOW Patched 3.7 2026-07-11 ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files w&hellip;
CVE-2026-61465 LOW Patched 3.3 2026-07-11 ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a cr&hellip;
CVE-2026-56372 LOW Patched 3.3 2026-07-11 ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magni&hellip;
CVE-2026-55807 LOW Patched 3.1 2026-07-10 Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, f&hellip;
CVE-2026-13235 LOW Patched 3.3 2026-07-10 Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to&hellip;
CVE-2026-13233 LOW 3.3 2026-07-10 Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.&hellip;
CVE-2026-13232 LOW 3.1 2026-07-10 Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka a&hellip;