Search
978 CVEs · Low severity
CVEs (978, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 978 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-76369 | LOW | Patched | 2.7 | 2026-08-19 | In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is po… |
| CVE-2026-76368 | LOW | Patched | 2.7 | 2026-08-19 | In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not a… |
| CVE-2026-76361 | LOW | Patched | 2.7 | 2026-08-19 | In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initi… |
| CVE-2026-76348 | LOW | Patched | 3.8 | 2026-08-19 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capabili… |
| CVE-2026-75476 | LOW | 3.1 | 2026-08-19 | Tanium addressed a compression bomb vulnerability in Threat Response. | |
| CVE-2026-18102 | LOW | 3.5 | 2026-08-19 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking. | |
| CVE-2026-11617 | LOW | 3.1 | 2026-08-19 | Tanium addressed a compression bomb vulnerability in Findings. | |
| CVE-2026-16891 | LOW | Patched | 3.3 | 2026-08-19 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read. |
| CVE-2026-16890 | LOW | Patched | 3.6 | 2026-08-19 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow. |
| CVE-2026-16888 | LOW | Patched | 3.7 | 2026-08-19 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability. |
| CVE-2026-75583 | LOW | 3.5 | 2026-08-19 | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach p… | |
| CVE-2026-49423 | LOW | 3.3 | 2026-08-19 | When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that we… | |
| CVE-2026-49431 | LOW | 3.3 | 2026-08-19 | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that t… | |
| CVE-2026-49426 | LOW | 3.3 | 2026-08-19 | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actu… | |
| CVE-2026-19406 | LOW | Patched | 2.7 | 2026-08-19 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowin… |
| CVE-2026-14826 | LOW | Patched | 2.7 | 2026-08-19 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification an… |
| CVE-2026-14825 | LOW | Patched | 2.7 | 2026-08-19 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing user… |
| CVE-2026-13173 | LOW | Patched | 2.7 | 2026-08-19 | The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speak… |
| CVE-2026-76014 | LOW | 3.3 | 2026-08-19 | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler.… | |
| CVE-2026-76042 | LOW | Patched | 3.1 | 2026-08-18 | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the … |
| CVE-2026-73923 | LOW | 3.7 | 2026-08-18 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Difficult to ex… | |
| CVE-2026-71146 | LOW | 1.9 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Diffi… | |
| CVE-2026-71144 | LOW | 3.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Diffi… | |
| CVE-2026-71140 | LOW | 3.4 | 2026-08-18 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnera… | |
| CVE-2026-71089 | LOW | 3.3 | 2026-08-18 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploit… |