Skip to main content

Severity archive

Low severity CVEs

Low

18,006 low severity CVEs — 43,633 Critical, 125,540 High, 163,851 Medium, 18,006 Low, 2,159 Unrated across the current result set.

CVE-2026-12774

Published Jun 21, 2026

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_expe…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-12772

Published Jun 21, 2026

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PRO…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-12771

Published Jun 21, 2026

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handl…

CVSS 1.3 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-12770

Published Jun 21, 2026

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
28.8
Vendor/product tagsBeta · best-effort

CVE-2026-56355

Published Jun 20, 2026

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

CVSS 3.7 · Low
evidence mentions
6
Buzz score
37.5

CVE-2026-56325

Published Jun 20, 2026

Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-56317

Published Jun 20, 2026

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-48794

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36…

CVSS 1.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-47203

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38…

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-49358

Published Jun 19, 2026

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTempo…

CVSS 3.0 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-49871

Published Jun 19, 2026

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpa…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49231

Published Jun 19, 2026

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugi…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-48895

Published Jun 19, 2026

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44915

Published Jun 19, 2026

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credentia…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44046

Published Jun 19, 2026

Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed id…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8668

Published Jun 18, 2026

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The c…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-48617

Published Jun 18, 2026

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intend…

CVSS 1.8 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-40457

Published Jun 18, 2026

A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where unsanitize…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
28.9

CVE-2026-12102

Published Jun 18, 2026

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

CVSS 2.7 · Low
evidence mentions
13
Buzz score
42.9

CVE-2026-50268

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1…

CVSS 1.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-12567

Published Jun 17, 2026

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can…

CVSS 2.2 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-12566

Published Jun 17, 2026

The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-i…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2024-24769

Published Jun 17, 2026

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their MFA token via API routes that send them an email. Currentl…

CVSS 2.1 · Low

CVE-2026-6733

Published Jun 17, 2026

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-39199

Published Jun 17, 2026

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

CVSS 2.9 · Low
evidence mentions
3
Buzz score
23.9
Showing 776-800 of 18,006 CVEsPage 32 of 721