Skip to main content

Severity archive

Low severity CVEs

Low

17,964 low severity CVEs — 43,431 Critical, 125,010 High, 163,480 Medium, 17,964 Low, 2,018 Unrated across the current result set.

CVE-2026-13350

Published Jun 25, 2026

Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57438

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced eac…

CVSS 2.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48940

Published Jun 25, 2026

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and re…

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57588

Published Jun 25, 2026

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan resu…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57587

Published Jun 25, 2026

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57535

Published Jun 25, 2026

Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rende…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57534

Published Jun 25, 2026

Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57533

Published Jun 25, 2026

Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57437

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57436

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57435

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57434

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitial…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57236

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a s…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57234

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::S…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13314

Published Jun 25, 2026

Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-12755

Published Jun 25, 2026

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission t…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42004

Published Jun 25, 2026

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted,…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-40208

Published Jun 25, 2026

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-40011

Published Jun 25, 2026

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometh…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-56130

Published Jun 25, 2026

"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expira…

CVSS 2.0 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-45188

Published Jun 25, 2026

Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which…

CVSS 2.4 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-3176

Published Jun 25, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have al…

CVSS 3.1 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-0934

Published Jun 25, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have al…

CVSS 3.8 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-39894

Published Jun 24, 2026

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 651-675 of 17,964 CVEsPage 27 of 719