Security Risk Severity

Low Security Risks

Published vulnerability pages grouped by low severity. Use this page to review risks that need similar prioritization.

91 published low risks

Low severity

Showing 1–36 of 91 published risks.

Clear
low

CVE-2026-15037 Qt vulnerability

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

CVE-2026-15037

Updated Jul 24, 2026

low

CVE-2026-16733 find-cypress-specs vulnerability

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-16733remote-code-execution

Updated Jul 24, 2026

low

CVE-2026-16735 conventional-changelog vulnerability

A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-16735remote-code-execution

Updated Jul 24, 2026

low

CVE-2026-65904 DOMPurify vulnerability

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to stringify the element (yielding '[object HTMLDivElement]'), silently reset IN_PLACE to false, and return the unsanitized element unchanged with any XSS payloads intact. The vendor considers this an edge case outside DOMPurify's threat model and, at time of publication, no fix was planned.

CVE-2026-65904xss

Updated Jul 24, 2026

low

CVE-2026-65699 AgentGPT vulnerability

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the run belongs to the requesting user, enabling an attacker who obtains a valid run_id to corrupt task history, exhaust the per-run loop budget, and drive LLM costs against the victim's run.

CVE-2026-65699authorization-bypassidor

Updated Jul 24, 2026

low

CVE-2026-15687 kubernetes-client/java vulnerability

A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.

CVE-2026-15687javacloud-securitypath-traversal

Updated Jul 24, 2026

low

CVE-2026-16763 serverless-localstack vulnerability

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-16763remote-code-execution

Updated Jul 24, 2026

low

CVE-2026-16764 DefectDojo vulnerability

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.

CVE-2026-16764api-securityprivilege-escalation

Updated Jul 24, 2026

low

CVE-2026-56392 coreutils vulnerability

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

CVE-2026-56392memory-corruption

Updated Jul 24, 2026

low

CVE-2026-47275 nanomq vulnerability

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client (including bridge mode) with a single packet, causing remote denial of service via SIGSEGV. In `nni_mqttv5_msg_decode_connect()` (`mqtt_codec.c:1863`), the code iterates over CONNECT properties using variable `prop` when it should use `will_prop`. When a CONNECT packet has no connect-level properties (`prop == NULL`) but has will properties (`will_prop != NULL`), dereferencing `prop->next` causes SIGSEGV at address `0x38` (NULL + `offsetof(property, next)`). This affects both `nanomq_cli` and **NanoMQ bridge mode** (Core component), as both use the same `mqtt_client.c` receive path. This can lead to remote DoS if a malicious MQTT broker can crash the client process with a single 35-byte packet and persistent DoS if auto-reconnect causes infinite crash loop.

CVE-2026-47275denial-of-service

Updated Jul 21, 2026

low

CVE-2026-16334 Hospital Management System vulnerability

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

CVE-2026-16334phpsql-injection

Updated Jul 21, 2026

low

CVE-2023-37508 DevOps Plan vulnerability

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

CVE-2023-37508browserdevopsxss

Updated Jul 21, 2026

lowEPSS 0.002

CVE-2026-35140 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.

CVE-2026-35140information-disclosure

Updated Jul 18, 2026

lowEPSS 0.002

CVE-2026-35141 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.

CVE-2026-35141authentication-bypass

Updated Jul 18, 2026

lowEPSS 0.002

CVE-2026-35142 dfxanalytics vulnerability

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.

CVE-2026-35142information-disclosure

Updated Jul 18, 2026

lowEPSS 0.001

CVE-2026-35143 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.

CVE-2026-35143information-disclosurecsrf

Updated Jul 18, 2026

lowEPSS 0.002

CVE-2026-35145 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.

CVE-2026-35145web-applicationinformation-disclosure

Updated Jul 18, 2026

lowEPSS 0.001

CVE-2026-61863 imagemagick vulnerability

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.

CVE-2026-61863denial-of-service

Updated Jul 17, 2026

low

CVE-2026-15642 in Devolutions Server

Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.

CVE-2026-15642web-applicationinformation-disclosure

Updated Jul 16, 2026

lowEPSS 0.004

CVE-2026-45072 in Symfony Web Profiler

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into <code> elements, allowing stored XSS against a developer who opens an attacker-written file such as var/log/dev.log in the profiler. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

CVE-2026-45072phpxss

Updated Jul 16, 2026

lowEPSS 0.004

CVE-2026-48329 in Adobe ColdFusion

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

CVE-2026-48329web-applicationauthentication-bypassauthorization-bypass

Updated Jul 16, 2026

low

CVE-2026-61866 in ImageMagick

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

CVE-2026-61866denial-of-service

Updated Jul 16, 2026

low

CVE-2026-40954 in Absolute Secure Access

CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

CVE-2026-40954network-securityinput-validationdenial-of-service

Updated Jul 16, 2026

low

CVE-2026-40955 in Absolute Secure Access

CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

CVE-2026-40955network-securityinput-validationdenial-of-service

Updated Jul 16, 2026

low

CVE-2026-40956 in Absolute Secure Access

CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

CVE-2026-40956network-securityinformation-disclosure

Updated Jul 16, 2026

low

CVE-2026-40958 in Absolute Secure Access

CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

CVE-2026-40958network-securityinput-validationdenial-of-service

Updated Jul 16, 2026

lowEPSS 0.002

CVE-2026-41579 runc /dev Symlink Host File Modification Vulnerability

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.

CVE-2026-41579linuxcloud-securitydevopssupply-chain

Updated Jul 15, 2026

lowEPSS 0.004

CVE-2026-44042 UltraVNC Repeater Base64 Decode Off-by-One

UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentication. In repeater/webgui/webutils.c:817, the wi_uudecode() function checks whether the input length exceeds the output buffer with a strict greater-than comparison (>), while the correct check should be greater-than-or-equal (>=). When strlen(authdata) equals sizeof(decode), the decoded output length (approximately 3/4 of input) does not overflow the buffer in current practice because the outer HTTP request bounds constrain the Authorization header. However, the defective check leaves a latent off-by-one condition that could become exploitable if the buffering constraints change. The current risk is limited to a one-byte write at the boundary of a 1024-byte stack buffer under constrained conditions.

CVE-2026-44042network-securityinput-validationmemory-corruption

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-61870 ImageMagick VIFF Memory Leak Vulnerability

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

CVE-2026-61870input-validationdenial-of-service

Updated Jul 15, 2026

low

CVE-2026-0275 in Prisma Browser

A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS.

CVE-2026-0275browserprivilege-escalation

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-55170 in OpenFGA Helm Charts

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare...

CVE-2026-55170api-securitycloud-securityinput-validation

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45064 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can leave visual-spoofing BiDi characters in sanitized URLs.

CVE-2026-45064phpweb-applicationinput-validation

Updated Jul 15, 2026

lowEPSS 0.006

CVE-2026-48001 in Adobe Commerce

Adobe Commerce can expose limited sensitive information under certain conditions.

CVE-2026-48001phpweb-applicationinformation-disclosure

Updated Jul 15, 2026

lowEPSS 0.004

CVE-2026-45065 in Symfony Routing

Symfony Routing can accept a route value that should fail validation, which can create an off-site redirect-style URL.

CVE-2026-45065phpweb-applicationinput-validationopen-redirect

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45066 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can bypass allowed link or media host rules because some URLs are parsed differently than expected.

CVE-2026-45066phpweb-applicationinput-validationauthorization-bypass

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45753 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss JavaScript URLs in some attributes, which can allow cross-site scripting in sanitized HTML.

CVE-2026-45753phpweb-applicationinput-validationxss

Updated Jul 15, 2026