Search
13 CVEs · published 2026-09-24 to 2026-09-24, Low severity
CVEs (13)
Showing 1–13 of 13
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-97233 | LOW | 3.5 | 2026-09-24 | A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filena… | |
| CVE-2026-63630 | LOW | Patched | 3.4 | 2026-09-24 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON with… |
| CVE-2026-73064 | LOW | 2.9 | 2026-09-24 | In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. Thi… | |
| CVE-2026-19492 | LOW | 3.2 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interfa… | |
| CVE-2026-77797 | LOW | 3.6 | 2026-09-24 | Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files. | |
| CVE-2026-18857 | LOW | 3.4 | 2026-09-24 | IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interfac… | |
| CVE-2026-18104 | LOW | 3.3 | 2026-09-24 | IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption. | |
| CVE-2026-17511 | LOW | 3.4 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-93661 | LOW | Patched | 2.7 | 2026-09-24 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a us… |
| CVE-2026-89004 | LOW | Patched | 2.7 | 2026-09-24 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, all… |
| CVE-2026-84151 | LOW | Patched | 3.5 | 2026-09-24 | The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with … |
| CVE-2026-96810 | LOW | 3.5 | 2026-09-24 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\s… | |
| CVE-2026-92628 | LOW | Patched | 3.1 | 2026-09-24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the M… |