Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-59846 LOW 3.9 2026-07-21 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing un…
CVE-2026-14971 LOW 3.9 2026-07-17 IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized oper…
CVE-2026-15028 LOW 3.9 2026-07-10 A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during…
CVE-2026-55592 LOW Patched 3.9 2026-07-07 Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without schem…
CVE-2026-12386 LOW Patched 3.9 2026-07-05 Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from …
CVE-2026-45642 LOW Patched 3.9 2026-06-09 Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
CVE-2026-30963 LOW Patched 3.9 2026-06-01 Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule …
CVE-2026-44069 LOW 3.9 2026-05-21 An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a …
CVE-2026-27964 LOW Patched 3.9 2026-05-18 FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNic…
CVE-2025-31974 LOW 3.9 2026-05-06 HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modificati…
CVE-2026-34768 LOW Patched 3.9 2026-04-04 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Wind…
CVE-2025-66037 LOW Patched 3.9 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out…
CVE-2025-66038 LOW Patched 3.9 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a s…
CVE-2026-3632 LOW 3.9 2026-03-17 A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowi…
CVE-2026-3633 LOW 3.9 2026-03-17 A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional requ…
CVE-2026-3634 LOW 3.9 2026-03-17 A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper in…
CVE-2025-31648 LOW 3.9 2026-02-10 Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged …
CVE-2025-13326 LOW Patched 3.9 2025-12-17 Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit&hellip;
CVE-2025-59700 LOW Patched 3.9 2025-12-02 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with root access to modify the Recovery Partition (&hellip;
CVE-2025-64711 LOW Patched 3.9 2025-11-13 PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, dragging a file whose filename co&hellip;
CVE-2025-11641 LOW Patched 3.9 2025-10-12 A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This manipulation causes im&hellip;
CVE-2025-5494 LOW Patched 3.9 2025-09-25 ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25&hellip;
CVE-2023-31365 LOW 3.9 2025-09-06 An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in loss of integrity or avai&hellip;
CVE-2025-32004 LOW 3.9 2025-08-12 Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2025-44964 LOW 3.9 2025-08-05 A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.