Search
972 CVEs · Low severity
CVEs (972, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 972 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21807 | LOW | 3.9 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | |
| CVE-2026-21809 | LOW | 3.9 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an atta… | |
| CVE-2026-18280 | LOW | 3.9 | 2026-08-20 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected in… | |
| CVE-2026-19411 | LOW | 3.9 | 2026-08-10 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack … | |
| CVE-2026-70598 | LOW | Patched | 3.9 | 2026-08-05 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rende… |
| CVE-2026-8029 | LOW | 3.9 | 2026-08-05 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database … | |
| CVE-2026-16791 | LOW | 3.9 | 2026-08-04 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o… | |
| CVE-2026-59846 | LOW | 3.9 | 2026-07-21 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing un… | |
| CVE-2026-14971 | LOW | 3.9 | 2026-07-17 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized oper… | |
| CVE-2026-15028 | LOW | 3.9 | 2026-07-10 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during… | |
| CVE-2026-55592 | LOW | Patched | 3.9 | 2026-07-07 | Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without schem… |
| CVE-2026-12386 | LOW | Patched | 3.9 | 2026-07-05 | Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from … |
| CVE-2026-14326 | LOW | 3.8 | 2026-09-02 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol… | |
| CVE-2026-81198 | LOW | Patched | 3.8 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u… |
| CVE-2026-82665 | LOW | 3.8 | 2026-08-31 | A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController… | |
| CVE-2026-78435 | LOW | 3.8 | 2026-08-24 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the … | |
| CVE-2026-69237 | LOW | Patched | 3.8 | 2026-08-21 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary … |
| CVE-2026-76348 | LOW | Patched | 3.8 | 2026-08-19 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capabili… |
| CVE-2026-62532 | LOW | 3.8 | 2026-08-18 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily… | |
| CVE-2026-19835 | LOW | 3.8 | 2026-08-14 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. S… | |
| CVE-2026-19763 | LOW | 3.8 | 2026-08-14 | A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component … | |
| CVE-2026-17043 | LOW | Patched | 3.8 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. |
| CVE-2026-6469 | LOW | Patched | 3.8 | 2026-08-13 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows th… |
| CVE-2026-16241 | LOW | Patched | 3.8 | 2026-08-13 | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking… |
| CVE-2026-14673 | LOW | Patched | 3.8 | 2026-08-13 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that d… |