Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-42546 LOW Patched 3.8 2026-07-06 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i…
CVE-2026-13322 LOW Patched 3.8 2026-06-26 A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un…
CVE-2026-0934 LOW Patched 3.8 2026-06-25 GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could …
CVE-2026-8823 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad&hellip;
CVE-2026-8074 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager wit&hellip;
CVE-2026-56212 LOW Patched 3.8 2026-06-20 Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authent&hellip;
CVE-2026-53809 LOW Patched 3.8 2026-06-11 OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of&hellip;
CVE-2025-12656 LOW 3.8 2026-06-06 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in t&hellip;
CVE-2026-45683 LOW Patched 3.8 2026-06-02 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled&hellip;
CVE-2026-10299 LOW 3.8 2026-06-01 A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This ma&hellip;
CVE-2026-40510 LOW Patched 3.8 2026-05-29 OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physicall&hellip;
CVE-2026-40528 LOW Patched 3.8 2026-05-29 OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows&hellip;
CVE-2026-6816 LOW Patched 3.8 2026-05-28 An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issu&hellip;
CVE-2026-44410 LOW 3.8 2026-05-26 This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's ex&hellip;
CVE-2026-3495 LOW Patched 3.8 2026-05-18 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an a&hellip;
CVE-2026-6923 LOW 3.8 2026-05-14 A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
CVE-2026-33585 LOW Patched 3.8 2026-05-13 Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an&hellip;
CVE-2026-44459 LOW Patched 3.8 2026-05-13 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat &hellip;
CVE-2026-34094 LOW Patched 3.8 2026-05-11 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * be&hellip;
CVE-2026-44987 LOW Patched 3.8 2026-05-08 SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Su&hellip;
CVE-2026-31051 LOW 3.8 2026-04-24 An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component
CVE-2026-22014 LOW 3.8 2026-04-21 Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-1&hellip;
CVE-2026-3470 LOW Patched 3.8 2026-03-31 A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attack&hellip;
CVE-2025-66215 LOW Patched 3.8 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a&hellip;
CVE-2025-49010 LOW Patched 3.8 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a&hellip;