Skip to main content

Severity archive

Low severity CVEs

Low

17,962 low severity CVEs — 43,427 Critical, 124,940 High, 163,447 Medium, 17,962 Low, 2,022 Unrated across the current result set.

CVE-2026-13482

Published Jun 28, 2026

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-58057

Published Jun 28, 2026

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensi…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
38.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-47206

Published Jun 26, 2026

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9

CVE-2023-20540

Published Jun 26, 2026

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary mess…

CVSS 1.8 · Low

CVE-2026-3472

Published Jun 26, 2026

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57940

Published Jun 26, 2026

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplie…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57926

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57922

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48936

Published Jun 26, 2026

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one su…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48935

Published Jun 26, 2026

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all s…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6331

Published Jun 25, 2026

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path t…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6325

Published Jun 25, 2026

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.

CVSS 2.0 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6092

Published Jun 25, 2026

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

CVSS 2.1 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6681

Published Jun 25, 2026

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfS…

CVSS 1.0 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6678

Published Jun 25, 2026

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

CVSS 1.0 · Low
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-6450

Published Jun 25, 2026

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to b…

CVSS 1.0 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6412

Published Jun 25, 2026

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

CVSS 2.3 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-7531

Published Jun 25, 2026

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybri…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-57522

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integ…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-10512

Published Jun 25, 2026

The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may not be fully reduced modulo the fi…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-55967

Published Jun 25, 2026

AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reu…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-13350

Published Jun 25, 2026

Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57438

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced eac…

CVSS 2.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48940

Published Jun 25, 2026

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and re…

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 626-650 of 17,962 CVEsPage 26 of 719