Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,623 CVEs · Low severity

EOL hidden · Show all products

CVEs (15,623, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 15,623 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-21807 LOW 3.9 2026-08-26 HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
CVE-2026-21809 LOW 3.9 2026-08-26 HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an atta…
CVE-2026-18280 LOW 3.9 2026-08-20 Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected in…
CVE-2026-19411 LOW 3.9 2026-08-10 A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack …
CVE-2026-70598 LOW Patched 3.9 2026-08-05 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rende…
CVE-2026-8029 LOW 3.9 2026-08-05 The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database …
CVE-2026-16791 LOW 3.9 2026-08-04 A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o…
CVE-2026-59846 LOW 3.9 2026-07-21 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing un…
CVE-2026-14971 LOW 3.9 2026-07-17 IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized oper…
CVE-2026-15028 LOW 3.9 2026-07-10 A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during…
CVE-2026-55592 LOW Patched 3.9 2026-07-07 Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without schem…
CVE-2026-12386 LOW Patched 3.9 2026-07-05 Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from …
CVE-2026-45642 LOW Patched 3.9 2026-06-09 Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
CVE-2026-30963 LOW Patched 3.9 2026-06-01 Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule …
CVE-2026-44069 LOW 3.9 2026-05-21 An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a …
CVE-2026-27964 LOW Patched 3.9 2026-05-18 FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNic…
CVE-2025-31974 LOW 3.9 2026-05-06 HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modificati…
CVE-2026-34768 LOW Patched 3.9 2026-04-04 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Wind…
CVE-2025-66037 LOW Patched 3.9 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out…
CVE-2025-66038 LOW Patched 3.9 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a s…
CVE-2026-3632 LOW 3.9 2026-03-17 A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowi…
CVE-2026-3633 LOW 3.9 2026-03-17 A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional requ…
CVE-2026-3634 LOW 3.9 2026-03-17 A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper in…
CVE-2025-31648 LOW 3.9 2026-02-10 Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged …
CVE-2025-13326 LOW Patched 3.9 2025-12-17 Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit&hellip;