Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

361 CVEs · Low severity

CVEs (361)

Showing 326–350 of 361

CVE ID Severity Patch CVSS Published Description
CVE-2026-13523 LOW 3.3 2026-06-29 A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipu…
CVE-2026-13514 LOW 2.4 2026-06-29 A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the compon…
CVE-2026-13511 LOW 3.1 2026-06-28 A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/m…
CVE-2026-13510 LOW 3.7 2026-06-28 A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.t…
CVE-2026-13504 LOW 3.5 2026-06-28 A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose P…
CVE-2026-13493 LOW 3.1 2026-06-28 A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the componen…
CVE-2026-13491 LOW 3.7 2026-06-28 A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc o…
CVE-2026-13490 LOW 3.7 2026-06-28 A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of…
CVE-2026-13489 LOW 3.1 2026-06-28 A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the component MCP Resp…
CVE-2026-13483 LOW 3.1 2026-06-28 A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the componen…
CVE-2026-13482 LOW 3.7 2026-06-28 A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handle…
CVE-2026-58052 LOW Patched 3.3 2026-06-28 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Ide…
CVE-2026-3472 LOW Patched 3.5 2026-06-26 Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which &hellip;
CVE-2026-57926 LOW Patched 2.6 2026-06-26 In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-57922 LOW Patched 3.1 2026-06-26 In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-48936 LOW 3.3 2026-06-26 A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects&hellip;
CVE-2026-48935 LOW 3.3 2026-06-26 A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affect&hellip;
CVE-2026-13322 LOW Patched 3.8 2026-06-26 A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un&hellip;
CVE-2026-57522 LOW Patched 3.5 2026-06-25 Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into even&hellip;
CVE-2026-48940 LOW Patched 3.4 2026-06-25 A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim&hellip;
CVE-2026-57588 LOW Patched 3.3 2026-06-25 A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the sc&hellip;
CVE-2026-57234 LOW Patched 2.6 2026-06-25 Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri:&hellip;
CVE-2026-12755 LOW Patched 2.7 2026-06-25 Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permi&hellip;
CVE-2026-42004 LOW 3.7 2026-06-25 An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is ins&hellip;
CVE-2026-40208 LOW 3.7 2026-06-25 An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.