Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

972 CVEs · Low severity

CVEs (972, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 972 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-41694 LOW Patched 3.7 2026-06-10 Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able…
CVE-2026-9060 LOW Patched 3.5 2026-06-10 The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2024-58350 LOW Patched 2.9 2026-06-10 Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and …
CVE-2026-49497 LOW Patched 3.3 2026-06-10 Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before const…
CVE-2026-50568 LOW Patched 3.6 2026-06-10 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Sanit…
CVE-2022-48575 LOW Patched 3.5 2026-06-10 A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.
CVE-2026-45380 LOW Patched 3.6 2026-06-10 bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, a one-byte off-by-one error in SafeOutPathBui…
CVE-2026-48011 LOW 3.7 2026-06-10 Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timin…
CVE-2026-47712 LOW Patched 3.3 2026-06-10 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=…
CVE-2026-41000 LOW Patched 3.7 2026-06-11 Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay o…
CVE-2026-3553 LOW Patched 3.1 2026-06-11 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions c…
CVE-2026-6976 LOW Patched 3.7 2026-06-11 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions c…
CVE-2026-9694 LOW Patched 2.6 2026-06-11 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, …
CVE-2026-11956 LOW 3.7 2026-06-11 A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Ex…
CVE-2026-44489 LOW Patched 3.7 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still const…
CVE-2026-53809 LOW Patched 3.8 2026-06-11 OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of…
CVE-2026-12017 LOW Patched 3.1 2026-06-11 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolat…
CVE-2026-12032 LOW Patched 3.1 2026-06-11 Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass s…
CVE-2026-9269 LOW Patched 3.5 2026-06-12 The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use…
CVE-2026-12065 LOW 1.8 2026-06-12 A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manip…
CVE-2026-12129 LOW 3.5 2026-06-12 A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the…
CVE-2026-12130 LOW 3.5 2026-06-12 A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Proj…
CVE-2026-53607 LOW 3.7 2026-06-12 ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a do…
CVE-2026-53837 LOW Patched 3.7 2026-06-12 OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass i…
CVE-2026-9061 LOW Patched 3.5 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b…