Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,585 CVEs · Low severity

CVEs (2,585, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 2,585 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-11909 LOW 3.3 2026-07-10 Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
CVE-2026-59180 LOW Patched 3.1 2026-07-10 Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-b…
CVE-2026-61492 LOW Patched 3.5 2026-07-10 In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
CVE-2026-59791 LOW Patched 3.5 2026-07-10 In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVE-2026-57961 LOW Patched 2.7 2026-07-10 phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user …
CVE-2026-56373 LOW Patched 3.7 2026-07-10 ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vu…
CVE-2026-56366 LOW Patched 3.3 2026-07-10 ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providin…
CVE-2026-15028 LOW 3.9 2026-07-10 A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during…
CVE-2026-15326 LOW 3.8 2026-07-10 A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installat…
CVE-2026-15321 LOW 2.4 2026-07-10 A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. The manipulat…
CVE-2026-15311 LOW 3.5 2026-07-10 A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/pl…
CVE-2026-15276 LOW 3.3 2026-07-09 A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of serv…
CVE-2026-15274 LOW 3.3 2026-07-09 A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. T…
CVE-2026-59715 LOW Patched 3.1 2026-07-09 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True…
CVE-2026-59226 LOW Patched 3.1 2026-07-09 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rech…
CVE-2026-59215 LOW Patched 3.1 2026-07-09 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to th…
CVE-2026-59213 LOW Patched 3.5 2026-07-09 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ol…
CVE-2026-15194 LOW 3.3 2026-07-09 A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulat…
CVE-2026-15185 LOW 3.3 2026-07-09 A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manip…
CVE-2026-15184 LOW 3.3 2026-07-09 A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Perfor…
CVE-2026-12590 LOW Patched 3.7 2026-07-09 Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable str…
CVE-2026-59269 LOW Patched 3.8 2026-07-09 A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions w…
CVE-2026-54780 LOW Patched 3.7 2026-07-08 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validat…
CVE-2026-15115 LOW Patched 3.3 2026-07-08 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a…
CVE-2026-15168 LOW Patched 2.5 2026-07-08 BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure