Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

399 CVEs · Low severity

CVEs (399)

Showing 1–25 of 399

CVE ID Severity Patch CVSS Published Description
CVE-2026-21807 LOW 3.9 2026-08-26 HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
CVE-2026-21809 LOW 3.9 2026-08-26 HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an atta…
CVE-2026-18280 LOW 3.9 2026-08-20 Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected in…
CVE-2026-19411 LOW 3.9 2026-08-10 A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack …
CVE-2026-14326 LOW 3.8 2026-09-02 The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol…
CVE-2026-81198 LOW Patched 3.8 2026-09-02 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u…
CVE-2026-82665 LOW 3.8 2026-08-31 A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController…
CVE-2026-78435 LOW 3.8 2026-08-24 A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the …
CVE-2026-69237 LOW Patched 3.8 2026-08-21 There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary …
CVE-2026-76348 LOW Patched 3.8 2026-08-19 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capabili…
CVE-2026-62532 LOW 3.8 2026-08-18 Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily…
CVE-2026-19835 LOW 3.8 2026-08-14 A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. S…
CVE-2026-19763 LOW 3.8 2026-08-14 A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component …
CVE-2026-17043 LOW Patched 3.8 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
CVE-2026-6469 LOW Patched 3.8 2026-08-13 Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows th…
CVE-2026-16241 LOW Patched 3.8 2026-08-13 Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking…
CVE-2026-14673 LOW Patched 3.8 2026-08-13 Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that d…
CVE-2026-70467 LOW 3.8 2026-08-12 A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, Fo…
CVE-2026-58245 LOW 3.8 2026-08-11 SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to acce…
CVE-2026-14211 LOW Patched 3.8 2026-08-10 The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec…
CVE-2026-17011 LOW Patched 3.8 2026-08-09 The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor r…
CVE-2026-86486 LOW Patched 3.7 2026-09-07 In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
CVE-2026-86420 LOW Patched 3.7 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can …
CVE-2026-86421 LOW Patched 3.7 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allow…
CVE-2026-86231 LOW 3.7 2026-09-06 A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performi…