Low Severity CVEs Low

437 documented vulnerabilities classified as low severity.

Other levels: Critical High Medium

Top Affected Vendors (Low Severity)

All Low CVEs

CVE-2026-45426
3.1 low

Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested path segment when verifying the JWT's `s

Apache Airflow Jun 1, 2026
CVE-2026-40963
3.1 low

The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag IDs and dependency metadata for other Da

Apache Airflow Jun 1, 2026
CVE-2026-10234
3.5 low

A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be use

Jun 1, 2026
CVE-2026-10233
3.3 low

A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to

Jun 1, 2026
CVE-2026-10228
3.5 low

A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of the argument Message results in cross site scripting. The attack can be ex

Jun 1, 2026
CVE-2026-48191
3.5 low

An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them. This issue affects OTRS with STORM modules: * 7.0.X

Jun 1, 2026
CVE-2026-48190
3.5 low

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected. This issue affects OTRS: * 7.0

Jun 1, 2026
CVE-2026-10216
3.7 low

A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched re

Jun 1, 2026
CVE-2026-10201
3.3 low

A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects of the file FBXExporter.cpp of the component UV Channel Handler. Executing a manipulation can lead to divide by zero. The attack needs to be launched locally. The exploit has been

Jun 1, 2026
CVE-2026-10199
3.3 low

A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out locally. The exploit has been disclosed to the publ

May 31, 2026
CVE-2026-10198
3.3 low

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has b

May 31, 2026
CVE-2026-10197
3.3 low

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local acces

May 31, 2026
CVE-2026-10169
3.7 low

A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The m

May 31, 2026
CVE-2026-10112
2.4 low

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the publi

May 30, 2026
CVE-2026-49383
3.3 low

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

Jetbrains Intellij Idea May 29, 2026
CVE-2026-49381
3.4 low

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49380
3.1 low

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49370
3.4 low

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Jetbrains Youtrack May 29, 2026
CVE-2026-40528
3.8 low

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init invocation, a key value entry

Opensc Project Opensc May 29, 2026
CVE-2026-40510
3.8 low

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field long

Opensc Project Opensc May 29, 2026
CVE-2026-9991
3.1 low

Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

May 28, 2026
CVE-2026-9959
3.1 low

Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Google Chrome May 28, 2026
CVE-2026-9950
3.1 low

Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

May 28, 2026
CVE-2026-9944
3.1 low

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

May 28, 2026