Search
87 CVEs · Low severity
CVEs (87)
Showing 1–25 of 87
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58234 | LOW | 2.2 | 2026-09-08 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditio… | |
| CVE-2026-84225 | LOW | Patched | 2.2 | 2026-09-05 | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administr… |
| CVE-2026-73748 | LOW | Patched | 2.2 | 2026-09-01 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext… |
| CVE-2026-86424 | LOW | Patched | 2.5 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write… |
| CVE-2026-73747 | LOW | Patched | 2.5 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato… |
| CVE-2026-18743 | LOW | 2.5 | 2026-09-01 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory… | |
| CVE-2026-84926 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user… |
| CVE-2026-84927 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contri… |
| CVE-2026-84745 | LOW | Patched | 2.7 | 2026-09-05 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with … |
| CVE-2026-78150 | LOW | Patched | 2.7 | 2026-09-05 | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges … |
| CVE-2025-15693 | LOW | Patched | 2.7 | 2026-09-05 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,… |
| CVE-2026-81196 | LOW | Patched | 2.7 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access … |
| CVE-2026-77784 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allow… |
| CVE-2026-77785 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning … |
| CVE-2026-77787 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object iden… |
| CVE-2026-86501 | LOW | Patched | 2.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
| CVE-2026-86141 | LOW | Patched | 2.9 | 2026-09-05 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. |
| CVE-2026-86137 | LOW | Patched | 2.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. |
| CVE-2026-86487 | LOW | Patched | 3.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content |
| CVE-2026-86227 | LOW | 3.1 | 2026-09-06 | A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argu… | |
| CVE-2026-84066 | LOW | Patched | 3.1 | 2026-09-04 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified … |
| CVE-2026-85052 | LOW | 3.1 | 2026-09-03 | Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the s… | |
| CVE-2026-49456 | LOW | Patched | 3.1 | 2026-09-03 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.… |
| CVE-2026-63020 | LOW | 3.1 | 2026-09-02 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenti… | |
| CVE-2026-78587 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctl… |