Skip to main content

Severity archive

Low severity CVEs

Low

17,964 low severity CVEs — 43,431 Critical, 125,012 High, 163,480 Medium, 17,964 Low, 2,018 Unrated across the current result set.

CVE-2026-54275

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is r…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53540

Published Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53538

Published Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addi…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53537

Published Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50269

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to m…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-49356

Published Jun 22, 2026

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @b…

CVSS 3.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9610

Published Jun 22, 2026

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8823

Published Jun 22, 2026

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbit…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8074

Published Jun 22, 2026

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12888

Published Jun 22, 2026

An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An a…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-44911

Published Jun 22, 2026

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration prope…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12823

Published Jun 22, 2026

A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation res…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-12822

Published Jun 22, 2026

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection.…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-12821

Published Jun 22, 2026

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-12815

Published Jun 22, 2026

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. T…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12814

Published Jun 21, 2026

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endp…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12813

Published Jun 21, 2026

A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/engine/src/lib/variables/processors…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12812

Published Jun 21, 2026

A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation. The manipulation leads…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-12811

Published Jun 21, 2026

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
30.0

CVE-2026-12810

Published Jun 21, 2026

A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Pe…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12809

Published Jun 21, 2026

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler.…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12808

Published Jun 21, 2026

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12807

Published Jun 21, 2026

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the a…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12805

Published Jun 21, 2026

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead t…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
40.0

CVE-2026-12804

Published Jun 21, 2026

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
29.5
Showing 701-725 of 17,964 CVEsPage 29 of 719