CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-103923 LOW

KaTeX: Existing prototype pollution can bypass trust restrictions

CVSS 2.1 EPSS n/a Oct 1, 2026
CVE-2026-21833 LOW

HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)

CVSS 3.7 EPSS n/a Oct 1, 2026
CVE-2026-67172 LOW

HCL BigFix Service Management is affected by multiple security vulnerabilities.

CVSS 3.7 EPSS n/a Oct 1, 2026
CVE-2026-42356 LOW

Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories

CVSS 3.7 EPSS n/a Oct 1, 2026
CVE-2026-56599 LOW

HCL BigFix Service Management is affected by multiple security vulnerabilities.

CVSS 2.2 EPSS n/a Oct 1, 2026
CVE-2026-66253 LOW

HCL iControl is affected by a Session Timeout vulnerability

CVSS 3.1 EPSS n/a Oct 1, 2026
CVE-2026-66249 LOW

HCL iControl is affected by a Missing Secure Attribute vulnerability

CVSS 3.1 EPSS n/a Oct 1, 2026
CVE-2026-66248 LOW

HCL iControl is affected by an Improper Error Handling vulnerability

CVSS 3.1 EPSS n/a Oct 1, 2026
CVE-2026-103680 LOW

Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation

CVSS 3.1 EPSS n/a Oct 1, 2026
CVE-2026-94220 LOW

Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin

CVSS 2.1 EPSS n/a Oct 1, 2026
CVE-2026-103489 LOW

In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible

CVSS 2.0 EPSS n/a Oct 1, 2026
CVE-2026-87973 LOW

If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name

CVSS 3.1 EPSS n/a Oct 1, 2026
CVE-2026-76144 LOW

Genians, Inc Genian SSL PNS Unrestricted File Upload

CVSS 1.8 EPSS n/a Oct 1, 2026
CVE-2026-103533 LOW

David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal

CVSS 2.1 EPSS n/a Oct 1, 2026
CVE-2026-101887 LOW

BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS

CVSS 2.1 EPSS n/a Oct 1, 2026
CVE-2026-103585 LOW

attacker-controlled javascript license URL via XSS

CVSS 1.2 EPSS n/a Sep 30, 2026
CVE-2026-103584 LOW

attacker-controlled javascript license URL via XSS

CVSS 1.1 EPSS n/a Sep 30, 2026
CVE-2026-102138 LOW

Kiteworks Core Server-Side Request Forgery (SSRF)

CVSS 3.3 EPSS 0.23% Sep 30, 2026
CVE-2026-103440 LOW

pagetriagelist discloses suppressed reviewer usernames

CVSS 1.2 EPSS 0.36% Sep 30, 2026
CVE-2026-103439 LOW

Various rawParams() and escaped() updates to prevent XSS in Wikibase extension

CVSS 0.3 EPSS 0.14% Sep 30, 2026
CVE-2026-103438 LOW

Various rawParams() and escaped() updates to prevent XSS in Wikistories extension

CVSS 0.3 EPSS 0.14% Sep 30, 2026
CVE-2026-103437 LOW

ReadingLists imported metadata permits JavaScript URL XSS

CVSS 1.1 EPSS 0.40% Sep 30, 2026
CVE-2026-103445 LOW

Stored XSS through PageForms #autoedit redirect links

CVSS 1.2 EPSS 0.40% Sep 30, 2026
CVE-2026-103444 LOW

Stored XSS through system messages in WikiForum

CVSS 1.1 EPSS 0.43% Sep 30, 2026
CVE-2026-103443 LOW

API permits session-seeded javascript URL XSS

CVSS 1.1 EPSS 0.32% Sep 30, 2026

Showing 1 to 25 CVEs · page 1 (more available)