Search
399 CVEs · Low severity
CVEs (399)
Showing 1–25 of 399
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2023-31308 | LOW | 3.3 | 2026-08-31 | A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read. | |
| CVE-2023-3360 | LOW | Patched | 3.3 | 2026-09-02 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use… |
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2025-15614 | LOW | Patched | 3.3 | 2026-09-05 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … |
| CVE-2025-15692 | LOW | Patched | 3.5 | 2026-09-02 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users… |
| CVE-2025-15693 | LOW | Patched | 2.7 | 2026-09-05 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,… |
| CVE-2025-15694 | LOW | Patched | 3.5 | 2026-09-05 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p… |
| CVE-2025-52651 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues. | |
| CVE-2025-52652 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a tru… | |
| CVE-2025-52657 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system perfor… | |
| CVE-2025-62315 | LOW | 3.4 | 2026-08-13 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by th… | |
| CVE-2025-62318 | LOW | 3.7 | 2026-08-13 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be c… | |
| CVE-2025-62341 | LOW | 3.7 | 2026-08-26 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in ce… | |
| CVE-2025-62343 | LOW | 3.1 | 2026-08-27 | HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion. | |
| CVE-2025-9486 | LOW | Patched | 3.3 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could h… |
| CVE-2026-11617 | LOW | 3.1 | 2026-08-19 | Tanium addressed a compression bomb vulnerability in Findings. | |
| CVE-2026-11809 | LOW | 3.7 | 2026-08-10 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the… | |
| CVE-2026-11811 | LOW | 3.7 | 2026-08-10 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure pa… | |
| CVE-2026-11812 | LOW | 2.5 | 2026-08-10 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block con… | |
| CVE-2026-11937 | LOW | Patched | 3.1 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Sec… |
| CVE-2026-11985 | LOW | 3.6 | 2026-08-11 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI p… | |
| CVE-2026-12372 | LOW | 3.7 | 2026-08-09 | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, in… | |
| CVE-2026-12971 | LOW | Patched | 2.2 | 2026-08-10 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the serv… |
| CVE-2026-13173 | LOW | Patched | 2.7 | 2026-08-19 | The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speak… |