Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 15,095 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-11909 | LOW | 3.3 | 2026-07-10 | Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. | |
| CVE-2026-59180 | LOW | Patched | 3.1 | 2026-07-10 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-b… |
| CVE-2026-61492 | LOW | Patched | 3.5 | 2026-07-10 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible |
| CVE-2026-59791 | LOW | Patched | 3.5 | 2026-07-10 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible |
| CVE-2026-57961 | LOW | Patched | 2.7 | 2026-07-10 | phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user … |
| CVE-2026-56373 | LOW | Patched | 3.7 | 2026-07-10 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vu… |
| CVE-2026-56366 | LOW | Patched | 3.3 | 2026-07-10 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providin… |
| CVE-2026-15028 | LOW | 3.9 | 2026-07-10 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during… | |
| CVE-2026-15326 | LOW | 3.8 | 2026-07-10 | A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installat… | |
| CVE-2026-15321 | LOW | 2.4 | 2026-07-10 | A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. The manipulat… | |
| CVE-2026-15311 | LOW | 3.5 | 2026-07-10 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/pl… | |
| CVE-2026-15276 | LOW | 3.3 | 2026-07-09 | A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of serv… | |
| CVE-2026-15274 | LOW | 3.3 | 2026-07-09 | A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. T… | |
| CVE-2026-59715 | LOW | Patched | 3.1 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True… |
| CVE-2026-59226 | LOW | Patched | 3.1 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rech… |
| CVE-2026-59215 | LOW | Patched | 3.1 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to th… |
| CVE-2026-59213 | LOW | Patched | 3.5 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ol… |
| CVE-2026-15194 | LOW | 3.3 | 2026-07-09 | A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulat… | |
| CVE-2026-15185 | LOW | 3.3 | 2026-07-09 | A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manip… | |
| CVE-2026-15184 | LOW | 3.3 | 2026-07-09 | A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Perfor… | |
| CVE-2026-12590 | LOW | Patched | 3.7 | 2026-07-09 | Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable str… |
| CVE-2026-59269 | LOW | Patched | 3.8 | 2026-07-09 | A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions w… |
| CVE-2026-54780 | LOW | Patched | 3.7 | 2026-07-08 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validat… |
| CVE-2026-15115 | LOW | Patched | 3.3 | 2026-07-08 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a… |
| CVE-2026-15168 | LOW | Patched | 2.5 | 2026-07-08 | BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure |