Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

405 CVEs · Low severity

CVEs (405)

Showing 251–275 of 405

CVE ID Severity Patch CVSS Published Description
CVE-2026-76369 LOW Patched 2.7 2026-08-19 In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is po…
CVE-2026-76368 LOW Patched 2.7 2026-08-19 In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not a…
CVE-2026-76361 LOW Patched 2.7 2026-08-19 In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initi…
CVE-2026-76348 LOW Patched 3.8 2026-08-19 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capabili…
CVE-2026-75476 LOW 3.1 2026-08-19 Tanium addressed a compression bomb vulnerability in Threat Response.
CVE-2026-18102 LOW 3.5 2026-08-19 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.
CVE-2026-11617 LOW 3.1 2026-08-19 Tanium addressed a compression bomb vulnerability in Findings.
CVE-2026-16891 LOW Patched 3.3 2026-08-19 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.
CVE-2026-16890 LOW Patched 3.6 2026-08-19 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.
CVE-2026-16888 LOW Patched 3.7 2026-08-19 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.
CVE-2026-75583 LOW 3.5 2026-08-19 keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach p…
CVE-2026-49423 LOW 3.3 2026-08-19 When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that we…
CVE-2026-49431 LOW 3.3 2026-08-19 The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that t…
CVE-2026-49426 LOW 3.3 2026-08-19 When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actu…
CVE-2026-19406 LOW Patched 2.7 2026-08-19 The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowin…
CVE-2026-14826 LOW Patched 2.7 2026-08-19 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification an…
CVE-2026-14825 LOW Patched 2.7 2026-08-19 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing user…
CVE-2026-13173 LOW Patched 2.7 2026-08-19 The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speak…
CVE-2026-76014 LOW 3.3 2026-08-19 A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler.…
CVE-2026-76042 LOW Patched 3.1 2026-08-18 Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the …
CVE-2026-73923 LOW 3.7 2026-08-18 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Difficult to ex…
CVE-2026-71146 LOW 1.9 2026-08-18 Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Diffi…
CVE-2026-71144 LOW 3.0 2026-08-18 Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Diffi…
CVE-2026-71140 LOW 3.4 2026-08-18 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnera…
CVE-2026-71089 LOW 3.3 2026-08-18 Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploit…