Search
118 CVEs · Low severity
CVEs (118)
Showing 1–25 of 118
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59846 | LOW | 3.9 | 2026-07-21 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing un… | |
| CVE-2026-14971 | LOW | 3.9 | 2026-07-17 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized oper… | |
| CVE-2026-61036 | LOW | 3.8 | 2026-07-21 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily e… | |
| CVE-2026-60405 | LOW | 3.8 | 2026-07-21 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is… | |
| CVE-2026-65061 | LOW | Patched | 3.8 | 2026-07-21 | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h w… |
| CVE-2026-65062 | LOW | Patched | 3.8 | 2026-07-21 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sorteds… |
| CVE-2026-65063 | LOW | Patched | 3.8 | 2026-07-21 | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h… |
| CVE-2026-65064 | LOW | Patched | 3.8 | 2026-07-21 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_gener… |
| CVE-2026-65066 | LOW | Patched | 3.8 | 2026-07-21 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h… |
| CVE-2026-65067 | LOW | Patched | 3.8 | 2026-07-21 | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h w… |
| CVE-2026-65068 | LOW | Patched | 3.8 | 2026-07-21 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphas… |
| CVE-2026-64614 | LOW | Patched | 3.8 | 2026-07-21 | Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h wit… |
| CVE-2026-64617 | LOW | Patched | 3.8 | 2026-07-21 | Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h w… |
| CVE-2026-52684 | LOW | 3.7 | 2026-07-23 | If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then th… | |
| CVE-2026-52686 | LOW | 3.7 | 2026-07-23 | The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME o… | |
| CVE-2026-54478 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie Sip… | |
| CVE-2026-44687 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by… | |
| CVE-2026-46582 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the R… | |
| CVE-2026-41637 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation… | |
| CVE-2026-42955 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound t… | |
| CVE-2026-61104 | LOW | 3.7 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.3… | |
| CVE-2026-61015 | LOW | 3.7 | 2026-07-21 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Di… | |
| CVE-2026-60919 | LOW | 3.7 | 2026-07-21 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. … | |
| CVE-2026-60628 | LOW | 3.7 | 2026-07-21 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. D… | |
| CVE-2026-60352 | LOW | 3.7 | 2026-07-21 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Dif… |