Search
399 CVEs · Low severity
CVEs (399)
Showing 1–25 of 399
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71083 | LOW | 1.8 | 2026-08-18 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to e… | |
| CVE-2026-71146 | LOW | 1.9 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Diffi… | |
| CVE-2026-71081 | LOW | 1.9 | 2026-08-18 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to e… | |
| CVE-2026-59291 | LOW | Patched | 2.0 | 2026-08-27 | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function… |
| CVE-2026-80201 | LOW | Patched | 2.0 | 2026-08-26 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attack… |
| CVE-2026-67442 | LOW | Patched | 2.0 | 2026-08-18 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage… |
| CVE-2026-48791 | LOW | Patched | 2.0 | 2026-08-13 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) a… |
| CVE-2026-58234 | LOW | 2.2 | 2026-09-08 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditio… | |
| CVE-2026-84225 | LOW | Patched | 2.2 | 2026-09-05 | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administr… |
| CVE-2026-73748 | LOW | Patched | 2.2 | 2026-09-01 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext… |
| CVE-2026-82631 | LOW | 2.2 | 2026-08-31 | A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blo… | |
| CVE-2026-77648 | LOW | 2.2 | 2026-08-20 | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance … | |
| CVE-2026-12971 | LOW | Patched | 2.2 | 2026-08-10 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the serv… |
| CVE-2026-19380 | LOW | 2.3 | 2026-08-10 | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to… | |
| CVE-2026-19382 | LOW | 2.3 | 2026-08-10 | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a… | |
| CVE-2026-82677 | LOW | 2.4 | 2026-08-31 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This… | |
| CVE-2026-43679 | LOW | Patched | 2.4 | 2026-08-21 | This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to vi… |
| CVE-2026-18283 | LOW | 2.4 | 2026-08-20 | Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations … | |
| CVE-2026-19904 | LOW | 2.4 | 2026-08-15 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the com… | |
| CVE-2026-86424 | LOW | Patched | 2.5 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write… |
| CVE-2026-73747 | LOW | Patched | 2.5 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato… |
| CVE-2026-18743 | LOW | 2.5 | 2026-09-01 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory… | |
| CVE-2026-71514 | LOW | Patched | 2.5 | 2026-08-22 | NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value re… |
| CVE-2026-66785 | LOW | 2.5 | 2026-08-20 | A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishin… | |
| CVE-2026-71082 | LOW | 2.5 | 2026-08-18 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to e… |