Search
361 CVEs · Low severity
CVEs (361)
Showing 326–350 of 361
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-13523 | LOW | 3.3 | 2026-06-29 | A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipu… | |
| CVE-2026-13514 | LOW | 2.4 | 2026-06-29 | A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the compon… | |
| CVE-2026-13511 | LOW | 3.1 | 2026-06-28 | A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/m… | |
| CVE-2026-13510 | LOW | 3.7 | 2026-06-28 | A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.t… | |
| CVE-2026-13504 | LOW | 3.5 | 2026-06-28 | A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose P… | |
| CVE-2026-13493 | LOW | 3.1 | 2026-06-28 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the componen… | |
| CVE-2026-13491 | LOW | 3.7 | 2026-06-28 | A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc o… | |
| CVE-2026-13490 | LOW | 3.7 | 2026-06-28 | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of… | |
| CVE-2026-13489 | LOW | 3.1 | 2026-06-28 | A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the component MCP Resp… | |
| CVE-2026-13483 | LOW | 3.1 | 2026-06-28 | A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the componen… | |
| CVE-2026-13482 | LOW | 3.7 | 2026-06-28 | A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handle… | |
| CVE-2026-58052 | LOW | Patched | 3.3 | 2026-06-28 | 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Ide… |
| CVE-2026-3472 | LOW | Patched | 3.5 | 2026-06-26 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which … |
| CVE-2026-57926 | LOW | Patched | 2.6 | 2026-06-26 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
| CVE-2026-57922 | LOW | Patched | 3.1 | 2026-06-26 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible |
| CVE-2026-48936 | LOW | 3.3 | 2026-06-26 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects… | |
| CVE-2026-48935 | LOW | 3.3 | 2026-06-26 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affect… | |
| CVE-2026-13322 | LOW | Patched | 3.8 | 2026-06-26 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un… |
| CVE-2026-57522 | LOW | Patched | 3.5 | 2026-06-25 | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into even… |
| CVE-2026-48940 | LOW | Patched | 3.4 | 2026-06-25 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim… |
| CVE-2026-57588 | LOW | Patched | 3.3 | 2026-06-25 | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the sc… |
| CVE-2026-57234 | LOW | Patched | 2.6 | 2026-06-25 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri:… |
| CVE-2026-12755 | LOW | Patched | 2.7 | 2026-06-25 | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permi… |
| CVE-2026-42004 | LOW | 3.7 | 2026-06-25 | An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is ins… | |
| CVE-2026-40208 | LOW | 3.7 | 2026-06-25 | An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame. |