Search
15,629 CVEs · Low severity
CVEs (15,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 15,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-76961 | LOW | 3.5 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low pr… | |
| CVE-2026-76960 | LOW | 3.5 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low pr… | |
| CVE-2026-58234 | LOW | 2.2 | 2026-09-08 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditio… | |
| CVE-2026-86505 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
| CVE-2026-86503 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching |
| CVE-2026-86501 | LOW | Patched | 2.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
| CVE-2026-86491 | LOW | Patched | 3.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads |
| CVE-2026-86487 | LOW | Patched | 3.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content |
| CVE-2026-86486 | LOW | Patched | 3.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
| CVE-2026-86485 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
| CVE-2026-86425 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted li… |
| CVE-2026-86424 | LOW | Patched | 2.5 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write… |
| CVE-2026-86423 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList metho… |
| CVE-2026-86422 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restricti… |
| CVE-2026-86421 | LOW | Patched | 3.7 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allow… |
| CVE-2026-86420 | LOW | Patched | 3.7 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can … |
| CVE-2026-86301 | LOW | 3.5 | 2026-09-07 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the compon… | |
| CVE-2025-52657 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system perfor… | |
| CVE-2025-52652 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a tru… | |
| CVE-2025-52651 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues. | |
| CVE-2026-86231 | LOW | 3.7 | 2026-09-06 | A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performi… | |
| CVE-2026-86227 | LOW | 3.1 | 2026-09-06 | A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argu… | |
| CVE-2026-86226 | LOW | 3.5 | 2026-09-06 | A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipula… | |
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2026-86181 | LOW | 3.5 | 2026-09-06 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the c… |