Search
361 CVEs · Low severity
CVEs (361)
Showing 1–25 of 361
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-10753 | LOW | Patched | 2.7 | 2026-06-24 | The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have bee… |
| CVE-2026-56368 | LOW | Patched | 3.7 | 2026-06-24 | ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can … |
| CVE-2026-56370 | LOW | Patched | 3.3 | 2026-06-24 | ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices… |
| CVE-2026-57288 | LOW | Patched | 3.7 | 2026-06-24 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, al… |
| CVE-2026-52796 | LOW | Patched | 3.5 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In … |
| CVE-2026-39894 | LOW | Patched | 2.9 | 2026-06-24 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can c… |
| CVE-2026-49979 | LOW | Patched | 2.7 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smt… |
| CVE-2026-8662 | LOW | Patched | 3.3 | 2026-06-25 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file … |
| CVE-2026-0934 | LOW | Patched | 3.8 | 2026-06-25 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could … |
| CVE-2026-3176 | LOW | Patched | 3.1 | 2026-06-25 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could … |
| CVE-2026-40011 | LOW | 3.7 | 2026-06-25 | An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the … | |
| CVE-2026-40208 | LOW | 3.7 | 2026-06-25 | An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame. | |
| CVE-2026-42004 | LOW | 3.7 | 2026-06-25 | An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is ins… | |
| CVE-2026-12755 | LOW | Patched | 2.7 | 2026-06-25 | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permi… |
| CVE-2026-57234 | LOW | Patched | 2.6 | 2026-06-25 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri:… |
| CVE-2026-57588 | LOW | Patched | 3.3 | 2026-06-25 | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the sc… |
| CVE-2026-48940 | LOW | Patched | 3.4 | 2026-06-25 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim… |
| CVE-2026-57522 | LOW | Patched | 3.5 | 2026-06-25 | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into even… |
| CVE-2026-13322 | LOW | Patched | 3.8 | 2026-06-26 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un… |
| CVE-2026-48935 | LOW | 3.3 | 2026-06-26 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affect… | |
| CVE-2026-48936 | LOW | 3.3 | 2026-06-26 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects… | |
| CVE-2026-57922 | LOW | Patched | 3.1 | 2026-06-26 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible |
| CVE-2026-57926 | LOW | Patched | 2.6 | 2026-06-26 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
| CVE-2026-3472 | LOW | Patched | 3.5 | 2026-06-26 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which … |
| CVE-2026-58052 | LOW | Patched | 3.3 | 2026-06-28 | 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Ide… |