Search
2,803 CVEs · Low severity
CVEs (2,803, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 2,803 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-79783 | LOW | Patched | 3.6 | 2026-08-25 | rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on… |
| CVE-2026-79782 | LOW | Patched | 3.1 | 2026-08-25 | rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintex… |
| CVE-2026-79777 | LOW | 2.7 | 2026-08-25 | rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, … | |
| CVE-2026-70548 | LOW | 3.5 | 2026-08-25 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | |
| CVE-2026-78887 | LOW | 3.7 | 2026-08-25 | A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipul… | |
| CVE-2026-78886 | LOW | 3.7 | 2026-08-25 | A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the … | |
| CVE-2026-21758 | LOW | 3.7 | 2026-08-25 | HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. | |
| CVE-2026-78638 | LOW | 3.3 | 2026-08-25 | A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Exec… | |
| CVE-2026-72701 | LOW | Patched | 3.7 | 2026-08-25 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() … |
| CVE-2026-78435 | LOW | 3.8 | 2026-08-24 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the … | |
| CVE-2026-76816 | LOW | Patched | 3.5 | 2026-08-24 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, wi… |
| CVE-2026-78187 | LOW | 3.1 | 2026-08-24 | A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads … | |
| CVE-2026-19565 | LOW | 3.7 | 2026-08-23 | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessi… | |
| CVE-2026-77003 | LOW | Patched | 2.7 | 2026-08-23 | The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contrib… |
| CVE-2026-78049 | LOW | 3.7 | 2026-08-22 | A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/add… | |
| CVE-2026-71514 | LOW | Patched | 2.5 | 2026-08-22 | NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value re… |
| CVE-2026-14187 | LOW | Patched | 2.7 | 2026-08-22 | The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the… |
| CVE-2026-33333 | LOW | Patched | 3.5 | 2026-08-21 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3. |
| CVE-2026-69238 | LOW | Patched | 3.5 | 2026-08-21 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into th… |
| CVE-2026-69237 | LOW | Patched | 3.8 | 2026-08-21 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary … |
| CVE-2026-18356 | LOW | Patched | 3.7 | 2026-08-21 | The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the accoun… |
| CVE-2026-13176 | LOW | Patched | 2.7 | 2026-08-21 | The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level … |
| CVE-2026-66721 | LOW | Patched | 2.7 | 2026-08-21 | Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, … |
| CVE-2026-19435 | LOW | Patched | 2.7 | 2026-08-21 | The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content… |
| CVE-2026-19085 | LOW | Patched | 2.7 | 2026-08-21 | The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to re… |