Search
399 CVEs · Low severity
CVEs (399)
Showing 1–25 of 399
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21807 | LOW | 3.9 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | |
| CVE-2026-21809 | LOW | 3.9 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an atta… | |
| CVE-2026-18280 | LOW | 3.9 | 2026-08-20 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected in… | |
| CVE-2026-19411 | LOW | 3.9 | 2026-08-10 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack … | |
| CVE-2026-14326 | LOW | 3.8 | 2026-09-02 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol… | |
| CVE-2026-81198 | LOW | Patched | 3.8 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u… |
| CVE-2026-82665 | LOW | 3.8 | 2026-08-31 | A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController… | |
| CVE-2026-78435 | LOW | 3.8 | 2026-08-24 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the … | |
| CVE-2026-69237 | LOW | Patched | 3.8 | 2026-08-21 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary … |
| CVE-2026-76348 | LOW | Patched | 3.8 | 2026-08-19 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capabili… |
| CVE-2026-62532 | LOW | 3.8 | 2026-08-18 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily… | |
| CVE-2026-19835 | LOW | 3.8 | 2026-08-14 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. S… | |
| CVE-2026-19763 | LOW | 3.8 | 2026-08-14 | A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component … | |
| CVE-2026-17043 | LOW | Patched | 3.8 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. |
| CVE-2026-6469 | LOW | Patched | 3.8 | 2026-08-13 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows th… |
| CVE-2026-16241 | LOW | Patched | 3.8 | 2026-08-13 | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking… |
| CVE-2026-14673 | LOW | Patched | 3.8 | 2026-08-13 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that d… |
| CVE-2026-70467 | LOW | 3.8 | 2026-08-12 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, Fo… | |
| CVE-2026-58245 | LOW | 3.8 | 2026-08-11 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to acce… | |
| CVE-2026-14211 | LOW | Patched | 3.8 | 2026-08-10 | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec… |
| CVE-2026-17011 | LOW | Patched | 3.8 | 2026-08-09 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor r… |
| CVE-2026-86486 | LOW | Patched | 3.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
| CVE-2026-86420 | LOW | Patched | 3.7 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can … |
| CVE-2026-86421 | LOW | Patched | 3.7 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allow… |
| CVE-2026-86231 | LOW | 3.7 | 2026-09-06 | A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performi… |