Skip to main content

Severity archive

Low severity CVEs

Low

18,049 low severity CVEs — 43,866 Critical, 126,461 High, 163,873 Medium, 18,049 Low, 1,893 Unrated across the current result set.

CVE-2026-56317

Published Jun 20, 2026

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-48794

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36…

CVSS 1.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-47203

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38…

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-49358

Published Jun 19, 2026

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTempo…

CVSS 3.0 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-49871

Published Jun 19, 2026

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpa…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49231

Published Jun 19, 2026

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugi…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-48895

Published Jun 19, 2026

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44915

Published Jun 19, 2026

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credentia…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44046

Published Jun 19, 2026

Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed id…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8668

Published Jun 18, 2026

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The c…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-48617

Published Jun 18, 2026

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intend…

CVSS 1.8 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-40457

Published Jun 18, 2026

A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where unsanitize…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
28.9

CVE-2026-12102

Published Jun 18, 2026

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

CVSS 2.7 · Low
evidence mentions
13
Buzz score
42.9

CVE-2026-50268

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1…

CVSS 1.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-12567

Published Jun 17, 2026

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can…

CVSS 2.2 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-12566

Published Jun 17, 2026

The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-i…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2024-24769

Published Jun 17, 2026

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their MFA token via API routes that send them an email. Currentl…

CVSS 2.1 · Low

CVE-2026-6733

Published Jun 17, 2026

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-39199

Published Jun 17, 2026

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

CVSS 2.9 · Low
evidence mentions
3
Buzz score
23.9

CVE-2026-11525

Published Jun 17, 2026

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact m…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-35068

Published Jun 17, 2026

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privil…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0057

Published Jun 17, 2026

In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local informa…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62340

Published Jun 17, 2026

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user ses…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-46977

Published Jun 17, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulner…

CVSS 3.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 826-850 of 18,049 CVEsPage 34 of 722