Search
87 CVEs · Low severity
CVEs (87)
Showing 1–25 of 87
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-18743 | LOW | 2.5 | 2026-09-01 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory… | |
| CVE-2026-48932 | LOW | 3.7 | 2026-09-01 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2026-81846 | LOW | Patched | 3.5 | 2026-09-01 | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through Us… |
| CVE-2026-73743 | LOW | Patched | 3.7 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handle… |
| CVE-2026-73744 | LOW | Patched | 3.5 | 2026-09-01 | A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator us… |
| CVE-2026-73745 | LOW | Patched | 3.1 | 2026-09-01 | A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system… |
| CVE-2026-73746 | LOW | Patched | 3.1 | 2026-09-01 | A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of ser… |
| CVE-2026-73747 | LOW | Patched | 2.5 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato… |
| CVE-2026-73748 | LOW | Patched | 2.2 | 2026-09-01 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext… |
| CVE-2026-84307 | LOW | Patched | 3.7 | 2026-09-01 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents … |
| CVE-2026-84367 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used… |
| CVE-2026-84368 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi pac… |
| CVE-2026-84328 | LOW | Patched | 3.1 | 2026-09-02 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v… |
| CVE-2026-84331 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via … |
| CVE-2026-84355 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy… |
| CVE-2026-84359 | LOW | Patched | 3.1 | 2026-09-02 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted … |
| CVE-2026-84437 | LOW | 3.5 | 2026-09-02 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc… | |
| CVE-2026-84438 | LOW | 3.5 | 2026-09-02 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W… | |
| CVE-2026-77783 | LOW | Patched | 3.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated vis… |
| CVE-2026-77784 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allow… |
| CVE-2026-77785 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning … |
| CVE-2026-77787 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object iden… |
| CVE-2026-81196 | LOW | Patched | 2.7 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access … |
| CVE-2026-81198 | LOW | Patched | 3.8 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u… |