Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

361 CVEs · Low severity

CVEs (361)

Showing 1–25 of 361

CVE ID Severity Patch CVSS Published Description
CVE-2026-10753 LOW Patched 2.7 2026-06-24 The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have bee…
CVE-2026-56368 LOW Patched 3.7 2026-06-24 ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can …
CVE-2026-56370 LOW Patched 3.3 2026-06-24 ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices…
CVE-2026-57288 LOW Patched 3.7 2026-06-24 Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, al…
CVE-2026-52796 LOW Patched 3.5 2026-06-24 Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In …
CVE-2026-39894 LOW Patched 2.9 2026-06-24 Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can c…
CVE-2026-49979 LOW Patched 2.7 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smt…
CVE-2026-8662 LOW Patched 3.3 2026-06-25 Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file …
CVE-2026-0934 LOW Patched 3.8 2026-06-25 GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could …
CVE-2026-3176 LOW Patched 3.1 2026-06-25 GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could …
CVE-2026-40011 LOW 3.7 2026-06-25 An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the …
CVE-2026-40208 LOW 3.7 2026-06-25 An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.
CVE-2026-42004 LOW 3.7 2026-06-25 An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is ins…
CVE-2026-12755 LOW Patched 2.7 2026-06-25 Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permi…
CVE-2026-57234 LOW Patched 2.6 2026-06-25 Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri:…
CVE-2026-57588 LOW Patched 3.3 2026-06-25 A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the sc…
CVE-2026-48940 LOW Patched 3.4 2026-06-25 A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim&hellip;
CVE-2026-57522 LOW Patched 3.5 2026-06-25 Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into even&hellip;
CVE-2026-13322 LOW Patched 3.8 2026-06-26 A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un&hellip;
CVE-2026-48935 LOW 3.3 2026-06-26 A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affect&hellip;
CVE-2026-48936 LOW 3.3 2026-06-26 A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects&hellip;
CVE-2026-57922 LOW Patched 3.1 2026-06-26 In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-57926 LOW Patched 2.6 2026-06-26 In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-3472 LOW Patched 3.5 2026-06-26 Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which &hellip;
CVE-2026-58052 LOW Patched 3.3 2026-06-28 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Ide&hellip;