Search
87 CVEs · Low severity
CVEs (87)
Showing 1–25 of 87
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2023-3360 | LOW | Patched | 3.3 | 2026-09-02 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use… |
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2025-15614 | LOW | Patched | 3.3 | 2026-09-05 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … |
| CVE-2025-15692 | LOW | Patched | 3.5 | 2026-09-02 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users… |
| CVE-2025-15693 | LOW | Patched | 2.7 | 2026-09-05 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,… |
| CVE-2025-15694 | LOW | Patched | 3.5 | 2026-09-05 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p… |
| CVE-2025-52651 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues. | |
| CVE-2025-52652 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a tru… | |
| CVE-2025-52657 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system perfor… | |
| CVE-2026-14326 | LOW | 3.8 | 2026-09-02 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol… | |
| CVE-2026-18540 | LOW | Patched | 3.7 | 2026-09-04 | undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original re… |
| CVE-2026-18743 | LOW | 2.5 | 2026-09-01 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory… | |
| CVE-2026-18858 | LOW | 3.3 | 2026-09-04 | IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. | |
| CVE-2026-19698 | LOW | Patched | 3.5 | 2026-09-02 | The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, a… |
| CVE-2026-48932 | LOW | 3.7 | 2026-09-01 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2026-49456 | LOW | Patched | 3.1 | 2026-09-03 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.… |
| CVE-2026-58234 | LOW | 2.2 | 2026-09-08 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditio… | |
| CVE-2026-63020 | LOW | 3.1 | 2026-09-02 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenti… | |
| CVE-2026-73743 | LOW | Patched | 3.7 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handle… |
| CVE-2026-73744 | LOW | Patched | 3.5 | 2026-09-01 | A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator us… |
| CVE-2026-73745 | LOW | Patched | 3.1 | 2026-09-01 | A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system… |
| CVE-2026-73746 | LOW | Patched | 3.1 | 2026-09-01 | A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of ser… |
| CVE-2026-73747 | LOW | Patched | 2.5 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato… |
| CVE-2026-73748 | LOW | Patched | 2.2 | 2026-09-01 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext… |