Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

972 CVEs · Low severity

CVEs (972, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 972 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2021-48006 LOW Patched 3.3 2026-09-06 PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on…
CVE-2022-48575 LOW Patched 3.5 2026-06-10 A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.
CVE-2023-31308 LOW 3.3 2026-08-31 A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.
CVE-2023-3360 LOW Patched 3.3 2026-09-02 The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use…
CVE-2023-54356 LOW Patched 3.7 2026-09-01 Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These…
CVE-2024-23573 LOW 3.7 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.…
CVE-2024-32389 LOW 3.5 2026-07-16 Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update UR…
CVE-2024-58350 LOW Patched 2.9 2026-06-10 Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and …
CVE-2025-0824 LOW 3.7 2026-06-29 Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block …
CVE-2025-12506 LOW Patched 3.5 2026-07-08 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions cou…
CVE-2025-12627 LOW Patched 2.4 2026-08-06 The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained …
CVE-2025-13475 LOW Patched 3.5 2026-07-04 In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a speci…
CVE-2025-13736 LOW Patched 3.7 2026-08-06 When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays thei…
CVE-2025-14562 LOW Patched 3.1 2026-07-29 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions coul…
CVE-2025-14779 LOW Patched 3.8 2026-08-06 The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce or…
CVE-2025-15614 LOW Patched 3.3 2026-09-05 ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files …
CVE-2025-15619 LOW 3.5 2026-06-23 HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
CVE-2025-15667 LOW 3.3 2026-07-06 A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the componen…
CVE-2025-15668 LOW 3.3 2026-07-06 A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Suc…
CVE-2025-15674 LOW Patched 2.7 2026-08-06 The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through …
CVE-2025-15677 LOW Patched 3.5 2026-08-05 The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege …
CVE-2025-15692 LOW Patched 3.5 2026-09-02 The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users…
CVE-2025-15693 LOW Patched 2.7 2026-09-05 The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,…
CVE-2025-15694 LOW Patched 3.5 2026-09-05 The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p…
CVE-2025-52651 LOW 3.5 2026-09-07 HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.