Search
2,797 CVEs · Low severity
CVEs (2,797, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 2,797 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10074 | LOW | Patched | 3.5 | 2025-09-08 | A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument… |
| CVE-2025-10075 | LOW | 3.5 | 2025-09-08 | A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulati… | |
| CVE-2025-10080 | LOW | 3.1 | 2025-09-08 | A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/d… | |
| CVE-2025-58422 | LOW | 3.1 | 2025-09-08 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the val… | |
| CVE-2025-10088 | LOW | 3.5 | 2025-09-08 | A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argumen… | |
| CVE-2025-51586 | LOW | Patched | 3.7 | 2025-09-08 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password… |
| CVE-2025-10099 | LOW | Patched | 2.4 | 2025-09-08 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of… |
| CVE-2024-48341 | LOW | 3.7 | 2025-09-08 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop | |
| CVE-2025-10117 | LOW | 3.5 | 2025-09-09 | A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. E… | |
| CVE-2025-42913 | LOW | 3.1 | 2025-09-09 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and p… | |
| CVE-2025-42914 | LOW | 3.1 | 2025-09-09 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and p… | |
| CVE-2025-42927 | LOW | 3.4 | 2025-09-09 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdat… | |
| CVE-2025-8889 | LOW | Patched | 3.8 | 2025-09-09 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the … |
| CVE-2025-9111 | LOW | Patched | 3.5 | 2025-09-09 | The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perfo… |
| CVE-2025-40802 | LOW | 3.1 | 2025-09-09 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to hi… | |
| CVE-2025-40803 | LOW | 3.1 | 2025-09-09 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This… | |
| CVE-2025-59014 | LOW | Patched | 2.7 | 2025-09-09 | An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a deni… |
| CVE-2025-8277 | LOW | 3.1 | 2025-09-09 | A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these re… | |
| CVE-2025-10222 | LOW | Patched | 3.3 | 2025-09-10 | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows all… |
| CVE-2025-10216 | LOW | 2.6 | 2025-09-10 | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The… | |
| CVE-2025-10234 | LOW | Patched | 2.4 | 2025-09-11 | A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. … |
| CVE-2025-10235 | LOW | Patched | 2.4 | 2025-09-11 | A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of… |
| CVE-2025-6088 | LOW | Patched | 3.1 | 2025-09-11 | In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if th… |
| CVE-2025-10246 | LOW | 3.5 | 2025-09-11 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /… | |
| CVE-2025-10252 | LOW | 3.1 | 2025-09-11 | A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deseriali… |