Search
978 CVEs · Low severity
CVEs (978, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 978 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9836 | LOW | Patched | 3.5 | 2026-06-30 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. |
| CVE-2026-9820 | LOW | Patched | 3.8 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager rol… |
| CVE-2026-9805 | LOW | 2.7 | 2026-08-26 | SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow. | |
| CVE-2026-9694 | LOW | Patched | 2.6 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, … |
| CVE-2026-9693 | LOW | Patched | 3.5 | 2026-08-17 | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a … |
| CVE-2026-9610 | LOW | 2.3 | 2026-06-22 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by di… | |
| CVE-2026-9269 | LOW | Patched | 3.5 | 2026-06-12 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use… |
| CVE-2026-9143 | LOW | Patched | 3.7 | 2026-06-19 | There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a siz… |
| CVE-2026-9062 | LOW | Patched | 3.4 | 2026-06-13 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read … |
| CVE-2026-9061 | LOW | Patched | 3.5 | 2026-06-13 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-9060 | LOW | Patched | 3.5 | 2026-06-10 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-8823 | LOW | Patched | 3.8 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad… |
| CVE-2026-8801 | LOW | Patched | 3.5 | 2026-07-08 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. |
| CVE-2026-8800 | LOW | Patched | 2.7 | 2026-07-08 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| CVE-2026-86644 | LOW | 3.5 | 2026-09-08 | A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API… | |
| CVE-2026-8662 | LOW | Patched | 3.3 | 2026-06-25 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file … |
| CVE-2026-8651 | LOW | Patched | 3.7 | 2026-07-08 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 befo… |
| CVE-2026-86505 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
| CVE-2026-86503 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching |
| CVE-2026-86501 | LOW | Patched | 2.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
| CVE-2026-86491 | LOW | Patched | 3.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads |
| CVE-2026-86487 | LOW | Patched | 3.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content |
| CVE-2026-86486 | LOW | Patched | 3.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
| CVE-2026-86485 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
| CVE-2026-86425 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted li… |