Search
361 CVEs · Low severity
CVEs (361)
Showing 226–250 of 361
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-6352 | LOW | Patched | 2.7 | 2026-07-08 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could … |
| CVE-2026-13151 | LOW | Patched | 2.7 | 2026-07-08 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could… |
| CVE-2025-12506 | LOW | Patched | 3.5 | 2026-07-08 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions cou… |
| CVE-2026-8801 | LOW | Patched | 3.5 | 2026-07-08 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. |
| CVE-2026-8800 | LOW | Patched | 2.7 | 2026-07-08 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| CVE-2026-8651 | LOW | Patched | 3.7 | 2026-07-08 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 befo… |
| CVE-2026-14967 | LOW | 3.1 | 2026-07-08 | BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, s… | |
| CVE-2026-14966 | LOW | 3.1 | 2026-07-08 | BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-… | |
| CVE-2026-56374 | LOW | Patched | 3.3 | 2026-07-08 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can … |
| CVE-2026-56362 | LOW | Patched | 3.3 | 2026-07-08 | ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache … |
| CVE-2026-53480 | LOW | Patched | 2.7 | 2026-07-08 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 rel… |
| CVE-2026-15041 | LOW | 3.7 | 2026-07-08 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time c… | |
| CVE-2026-60000 | LOW | Patched | 3.7 | 2026-07-08 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mish… |
| CVE-2026-28378 | LOW | Patched | 3.1 | 2026-07-07 | The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a differe… |
| CVE-2026-55592 | LOW | Patched | 3.9 | 2026-07-07 | Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without schem… |
| CVE-2026-14935 | LOW | 3.7 | 2026-07-07 | A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote … | |
| CVE-2026-48588 | LOW | Patched | 3.1 | 2026-07-07 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when… |
| CVE-2026-42201 | LOW | Patched | 3.3 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, key… |
| CVE-2026-27844 | LOW | 2.7 | 2026-07-07 | Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller res… | |
| CVE-2026-27790 | LOW | 2.7 | 2026-07-07 | Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary … | |
| CVE-2026-42172 | LOW | Patched | 3.1 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a l… |
| CVE-2026-42145 | LOW | Patched | 3.1 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/… |
| CVE-2026-34149 | LOW | Patched | 3.3 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled … |
| CVE-2026-42148 | LOW | Patched | 3.8 | 2026-07-06 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Set… |
| CVE-2026-34049 | LOW | Patched | 3.3 | 2026-07-06 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for… |