Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17043 | LOW | Patched | 3.8 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. |
| CVE-2026-6469 | LOW | Patched | 3.8 | 2026-08-13 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows th… |
| CVE-2026-16241 | LOW | Patched | 3.8 | 2026-08-13 | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking… |
| CVE-2026-14673 | LOW | Patched | 3.8 | 2026-08-13 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that d… |
| CVE-2026-70467 | LOW | 3.8 | 2026-08-12 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, Fo… | |
| CVE-2026-58245 | LOW | 3.8 | 2026-08-11 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to acce… | |
| CVE-2026-14211 | LOW | Patched | 3.8 | 2026-08-10 | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec… |
| CVE-2026-17011 | LOW | Patched | 3.8 | 2026-08-09 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor r… |
| CVE-2025-14779 | LOW | Patched | 3.8 | 2026-08-06 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce or… |
| CVE-2026-12730 | LOW | 3.8 | 2026-08-05 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 … | |
| CVE-2026-67334 | LOW | Patched | 3.8 | 2026-08-01 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeS… |
| CVE-2026-14197 | LOW | Patched | 3.8 | 2026-08-01 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to … |
| CVE-2026-14221 | LOW | 3.8 | 2026-07-30 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any aut… | |
| CVE-2026-14222 | LOW | Patched | 3.8 | 2026-07-30 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contribu… |
| CVE-2026-14189 | LOW | Patched | 3.8 | 2026-07-27 | The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator ac… |
| CVE-2026-12690 | LOW | Patched | 3.8 | 2026-07-24 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logge… |
| CVE-2026-61036 | LOW | Patched | 3.8 | 2026-07-21 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily e… |
| CVE-2026-60405 | LOW | 3.8 | 2026-07-21 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is… | |
| CVE-2026-65061 | LOW | Patched | 3.8 | 2026-07-21 | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h w… |
| CVE-2026-65062 | LOW | Patched | 3.8 | 2026-07-21 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sorteds… |
| CVE-2026-65063 | LOW | Patched | 3.8 | 2026-07-21 | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h… |
| CVE-2026-65064 | LOW | Patched | 3.8 | 2026-07-21 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_gener… |
| CVE-2026-65066 | LOW | Patched | 3.8 | 2026-07-21 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h… |
| CVE-2026-65067 | LOW | Patched | 3.8 | 2026-07-21 | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h w… |
| CVE-2026-65068 | LOW | Patched | 3.8 | 2026-07-21 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphas… |