Skip to main content

Severity archive

Low severity CVEs

Low

17,964 low severity CVEs — 43,431 Critical, 125,012 High, 163,480 Medium, 17,964 Low, 2,018 Unrated across the current result set.

CVE-2026-52796

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In interna…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-49277

Published Jun 24, 2026

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not rev…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-45757

Published Jun 24, 2026

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-49246

Published Jun 24, 2026

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing path sa…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54906

Published Jun 24, 2026

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write loc…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54905

Published Jun 24, 2026

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lo…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57288

Published Jun 24, 2026

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13140

Published Jun 24, 2026

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. Th…

CVSS 1.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-10753

Published Jun 24, 2026

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been grant…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-47388

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment path could read any file in shared…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-46554

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the a…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-46553

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file's adv…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-46549

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but t…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54327

Published Jun 23, 2026

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could briefly cre…

CVSS 2.2 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-54326

Published Jun 23, 2026

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown…

CVSS 2.5 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-57062

Published Jun 23, 2026

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is acce…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
28.9

CVE-2026-56968

Published Jun 23, 2026

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2025-15619

Published Jun 23, 2026

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

CVSS 3.5 · Low

CVE-2026-47241

Published Jun 22, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-48931

Published Jun 22, 2026

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported rele…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
37.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-53663

Published Jun 22, 2026

React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed o…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54282

Published Jun 22, 2026

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebu…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54280

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle…

CVSS 1.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-54279

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later wit…

CVSS 1.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 676-700 of 17,964 CVEsPage 28 of 719