Search
361 CVEs · Low severity
CVEs (361)
Showing 301–325 of 361
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-56365 | LOW | Patched | 3.7 | 2026-06-30 | ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust … |
| CVE-2026-56364 | LOW | Patched | 1.9 | 2026-06-30 | ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclose… |
| CVE-2026-56363 | LOW | Patched | 3.3 | 2026-06-30 | ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply… |
| CVE-2026-56361 | LOW | Patched | 3.3 | 2026-06-30 | ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by pr… |
| CVE-2026-54696 | LOW | Patched | 3.7 | 2026-06-30 | Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized stre… |
| CVE-2026-13982 | LOW | Patched | 3.1 | 2026-06-30 | Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a c… |
| CVE-2026-13963 | LOW | Patched | 3.1 | 2026-06-30 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cr… |
| CVE-2026-13955 | LOW | Patched | 3.3 | 2026-06-30 | Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious … |
| CVE-2026-13948 | LOW | Patched | 3.1 | 2026-06-30 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform U… |
| CVE-2026-13945 | LOW | Patched | 3.1 | 2026-06-30 | Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to … |
| CVE-2026-13944 | LOW | Patched | 3.1 | 2026-06-30 | Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures… |
| CVE-2026-13942 | LOW | Patched | 3.3 | 2026-06-30 | Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a crafted HTML page. (… |
| CVE-2026-13939 | LOW | Patched | 3.1 | 2026-06-30 | Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process… |
| CVE-2026-9836 | LOW | Patched | 3.5 | 2026-06-30 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. |
| CVE-2026-58371 | LOW | Patched | 3.1 | 2026-06-30 | SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application/javascript in the shared writeJson helper (weed/ser… |
| CVE-2026-10654 | LOW | Patched | 3.1 | 2026-06-30 | A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a simultaneous bidirectional session disconnect. When… |
| CVE-2026-13758 | LOW | Patched | 3.7 | 2026-06-29 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it… |
| CVE-2026-57946 | LOW | 3.7 | 2026-06-29 | Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessin… | |
| CVE-2026-13746 | LOW | Patched | 3.6 | 2026-06-29 | Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying craft… |
| CVE-2026-13587 | LOW | 3.7 | 2026-06-29 | A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the file light_pcapng.c of the component LightPcapNg Par… | |
| CVE-2026-13574 | LOW | 3.3 | 2026-06-29 | A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the c… | |
| CVE-2026-13573 | LOW | 3.3 | 2026-06-29 | A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component … | |
| CVE-2026-13570 | LOW | 3.5 | 2026-06-29 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Reg… | |
| CVE-2026-13558 | LOW | 3.5 | 2026-06-29 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component … | |
| CVE-2025-0824 | LOW | 3.7 | 2026-06-29 | Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block … |