Search
361 CVEs · Low severity
CVEs (361)
Showing 1–25 of 361
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23573 | LOW | 3.7 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.… | |
| CVE-2024-32389 | LOW | 3.5 | 2026-07-16 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update UR… | |
| CVE-2025-0824 | LOW | 3.7 | 2026-06-29 | Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block … | |
| CVE-2025-12506 | LOW | Patched | 3.5 | 2026-07-08 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions cou… |
| CVE-2025-13475 | LOW | Patched | 3.5 | 2026-07-04 | In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a speci… |
| CVE-2025-15667 | LOW | 3.3 | 2026-07-06 | A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the componen… | |
| CVE-2025-15668 | LOW | 3.3 | 2026-07-06 | A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Suc… | |
| CVE-2025-59866 | LOW | 3.3 | 2026-07-17 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in… | |
| CVE-2025-62675 | LOW | Patched | 3.4 | 2026-07-14 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, Fort… |
| CVE-2025-62826 | LOW | Patched | 3.1 | 2026-07-14 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, Fort… |
| CVE-2026-0934 | LOW | Patched | 3.8 | 2026-06-25 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could … |
| CVE-2026-10654 | LOW | Patched | 3.1 | 2026-06-30 | A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a simultaneous bidirectional session disconnect. When… |
| CVE-2026-10657 | LOW | Patched | 3.7 | 2026-07-05 | Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), ".local", 7), which alway… |
| CVE-2026-10668 | LOW | Patched | 2.4 | 2026-07-12 | The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsu… |
| CVE-2026-10679 | LOW | 3.3 | 2026-07-21 | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->frequency without validating config->frequency. sp… | |
| CVE-2026-10753 | LOW | Patched | 2.7 | 2026-06-24 | The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have bee… |
| CVE-2026-10755 | LOW | Patched | 2.7 | 2026-07-20 | The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privile… |
| CVE-2026-11578 | LOW | Patched | 2.7 | 2026-07-02 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage… |
| CVE-2026-11781 | LOW | Patched | 2.7 | 2026-07-02 | The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing… |
| CVE-2026-11880 | LOW | Patched | 3.1 | 2026-07-01 | The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with … |
| CVE-2026-11909 | LOW | 3.3 | 2026-07-10 | Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. | |
| CVE-2026-11925 | LOW | 2.7 | 2026-07-21 | Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server. | |
| CVE-2026-12386 | LOW | Patched | 3.9 | 2026-07-05 | Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from … |
| CVE-2026-12482 | LOW | 3.1 | 2026-07-14 | A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/uti… | |
| CVE-2026-12547 | LOW | 3.4 | 2026-07-21 | SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system sett… |