Search
361 CVEs · Low severity
CVEs (361)
Showing 1–25 of 361
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59846 | LOW | 3.9 | 2026-07-21 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing un… | |
| CVE-2026-14971 | LOW | 3.9 | 2026-07-17 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized oper… | |
| CVE-2026-15028 | LOW | 3.9 | 2026-07-10 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during… | |
| CVE-2026-55592 | LOW | Patched | 3.9 | 2026-07-07 | Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without schem… |
| CVE-2026-12386 | LOW | Patched | 3.9 | 2026-07-05 | Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from … |
| CVE-2026-61036 | LOW | 3.8 | 2026-07-21 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily e… | |
| CVE-2026-60405 | LOW | 3.8 | 2026-07-21 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is… | |
| CVE-2026-65061 | LOW | Patched | 3.8 | 2026-07-21 | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h w… |
| CVE-2026-65062 | LOW | Patched | 3.8 | 2026-07-21 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sorteds… |
| CVE-2026-65063 | LOW | Patched | 3.8 | 2026-07-21 | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h… |
| CVE-2026-65064 | LOW | Patched | 3.8 | 2026-07-21 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_gener… |
| CVE-2026-65066 | LOW | Patched | 3.8 | 2026-07-21 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h… |
| CVE-2026-65067 | LOW | Patched | 3.8 | 2026-07-21 | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h w… |
| CVE-2026-65068 | LOW | Patched | 3.8 | 2026-07-21 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphas… |
| CVE-2026-64614 | LOW | Patched | 3.8 | 2026-07-21 | Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h wit… |
| CVE-2026-64617 | LOW | Patched | 3.8 | 2026-07-21 | Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h w… |
| CVE-2026-9820 | LOW | Patched | 3.8 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager rol… |
| CVE-2026-56281 | LOW | Patched | 3.8 | 2026-07-12 | Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request bo… |
| CVE-2026-15326 | LOW | 3.8 | 2026-07-10 | A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installat… | |
| CVE-2026-59269 | LOW | Patched | 3.8 | 2026-07-09 | A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions w… |
| CVE-2026-42148 | LOW | Patched | 3.8 | 2026-07-06 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Set… |
| CVE-2026-53763 | LOW | Patched | 3.8 | 2026-07-06 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i… |
| CVE-2026-42546 | LOW | Patched | 3.8 | 2026-07-06 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i… |
| CVE-2026-13322 | LOW | Patched | 3.8 | 2026-06-26 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un… |
| CVE-2026-0934 | LOW | Patched | 3.8 | 2026-06-25 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could … |