2026 · Low
Low-severity vulnerabilities disclosed in 2026
Low-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
385 published vulnerabilities · page 2 of 4
- CVE-2026-45380LOW 3.6
bit7z is a C++ library used for archive compression and extraction. Before version 4.0.12, it contained a one-byte error in how it handles symlinks when extracting 7z archives on non-Windows systems. An attacker could craft a malicious archive that creates a symlink pointing outside the intended extraction directory. Once that symlink exists, subsequent files from the same archive could be written to arbitrary locations on the system, potentially overwriting important files or placing malicious content where it will be executed.
- CVE-2026-50568LOW 3.6
Fission, an open-source serverless framework for Kubernetes, contained a path validation flaw that could allow a tenant with local access to read or write files outside an intended safe directory. The vulnerability stems from a lexical string comparison that doesn't respect directory boundaries—for example, a directory named '/packages-extra' would incorrectly pass validation meant for '/packages'. An attacker who can pre-create or control a sibling directory in the shared storage volume could exploit this to access sensitive files. This affects versions prior to 1.25.0 and has been patched.
- CVE-2022-48575LOW 3.5
CVE-2022-48575 is a local bypass vulnerability in macOS that allows someone with physical access to a Mac to circumvent the Login Window security prompt. The issue stems from inconsistent state handling in the authentication system—essentially, the login screen may fail to properly enforce its security state in certain conditions, potentially allowing unauthorized access. Apple has patched this in macOS Monterey 12.4 and later.
- CVE-2025-12506LOW 3.5
GitLab has addressed a content display inconsistency vulnerability affecting versions 16.5 through 19.1 (depending on release branch). An authenticated user could create a repository where files or content shown in the web interface don't match what users actually download, due to improper handling of Git reference names. While this requires authentication and user interaction to observe, it creates a trust boundary violation where the visual representation of code in the web UI becomes unreliable.
- CVE-2025-13475LOW 3.5
CVE-2025-13475 is a consent isolation flaw in multi-tenant deployments where user consent granted for a SaaS application in one tenant can leak to applications with the same name in other tenants. This cross-tenant consent sharing allows applications to access user data without proper authorization. The issue is confined to systems running in multi-tenant mode; single-tenant deployments are unaffected.
- CVE-2025-15619LOW 3.5
HCL Connections has a broken access control flaw that creates a narrow but real window for unauthorized viewing of sensitive data. An authenticated attacker can, under specific conditions and with user interaction, bypass intended access restrictions and view information they shouldn't be able to access. The vulnerability is not network-exploitable without valid login credentials, and the exposure is limited to a single defined scenario rather than widespread data exposure.
- CVE-2026-0129LOW 3.5
A missing bounds check in Android's RTCP (Real-time Transport Control Protocol) Bye packet decoder can expose sensitive information to an authenticated attacker. The vulnerability requires user interaction to trigger and affects only confidentiality; no system crash or modification is possible. This is a low-severity information disclosure issue that primarily concerns privacy of real-time communications data.
- CVE-2026-0130LOW 3.5
CVE-2026-0130 is a low-severity vulnerability affecting Google Android that allows an attacker to read sensitive data from device memory through a malformed network packet. The flaw exists in the RtcpChunk decoder, which fails to properly validate buffer boundaries before reading data. An attacker must trick a user into accepting or opening a specially crafted media stream or communication session to trigger the vulnerability. Successful exploitation results in disclosure of locally stored information but does not enable device compromise, privilege escalation, or data modification.
- CVE-2026-10228LOW 3.5
A cross-site scripting (XSS) vulnerability exists in the raisulislamg4 student_management_system_by_php project. The flaw resides in the admission_form_check.php file, where user input passed through the Message parameter is not properly sanitized before being reflected in the web response. An authenticated attacker can craft malicious input that, when viewed by another user, executes arbitrary JavaScript in their browser. The vulnerability requires user interaction (clicking a malicious link) and affects only the integrity of data, not confidentiality or availability. Public exploit details are available, though the CVSS 3.5 score reflects the relatively constrained attack scenario requiring authentication and browser-based execution.
- CVE-2026-10234LOW 3.5
Mettle sendportal versions up to 3.0.1 contain a cross-site scripting (XSS) vulnerability in the Campaign Handler component. An authenticated attacker can inject malicious scripts through the content parameter in the /webview/ endpoint, potentially allowing them to steal session cookies, perform actions on behalf of users, or redirect users to malicious sites. The vulnerability requires user interaction to be effective and does not grant direct administrative access. Exploit code is publicly available, elevating practical risk despite the low CVSS score.
- CVE-2026-10244LOW 3.5
SourceCodester Pharmacy Sales and Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in the medicine name creation function. An authenticated user can inject malicious script code through the medicine_name parameter, which executes in the context of other users' browsers. The vulnerability requires user interaction (clicking a link or visiting a page) to trigger, and an attacker must have valid login credentials to exploit it. Public exploits are now available.
- CVE-2026-10245LOW 3.5
SourceCodester Pharmacy Sales and Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in its supplier creation functionality. An authenticated user can inject malicious code through the company name field when creating a supplier record. This code executes in the browsers of other users who view the supplier information, potentially allowing attackers to steal session tokens, redirect users to malicious sites, or perform unauthorized actions on their behalf. Public exploits for this vulnerability are already available.
- CVE-2026-10246LOW 3.5
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An authenticated user can inject malicious scripts through the medicine presentation creation function, which are then executed in the browsers of other users who view that data. The attack requires user interaction and does not grant elevated privileges, but can be used to steal session tokens, redirect users, or perform actions on their behalf within the application.
- CVE-2026-10247LOW 3.5
A cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An authenticated attacker can inject malicious scripts through the generic_name parameter in the create_generic_name function, which the application will then execute in users' browsers. This could allow the attacker to steal session cookies, hijack user accounts, or manipulate pharmacy data. The vulnerability requires user interaction to trigger and an authenticated account to exploit, limiting its immediate impact, but public exploit code is now available.
- CVE-2026-10264LOW 3.5
CVE-2026-10264 is a path traversal vulnerability in lharries whatsapp-mcp version 0.0.1, located in the SendMessageRequest function of the Send API Endpoint. An attacker with local access and user privileges can manipulate the mediaPath argument to traverse the file system and read sensitive files, though exploitation impact is limited to information disclosure. The vulnerability has been publicly disclosed.
- CVE-2026-10567LOW 3.5
A stored cross-site scripting (XSS) vulnerability exists in 1Panel-dev CordysCRM versions up to 1.4.1. An authenticated attacker can inject malicious JavaScript into the Description field of the ModuleFormController, which will execute in the browsers of other users who view the affected module form. The vulnerability requires user interaction (viewing the crafted form) to trigger, and does not grant the attacker direct access to sensitive data or system functions. Upgrading to version 1.7.0 resolves the issue.
- CVE-2026-11511LOW 3.5
Bolt CMS versions up to 3.7.5 contain a vulnerability in how it handles HTML attributes within text fields. An authenticated attacker can manipulate the 'style' argument to inject arbitrary HTML code, potentially affecting the visual presentation or behavior of a web page. The vulnerability requires user interaction (a user must view the injected content) and authentication, limiting its immediate risk. However, because Bolt CMS is no longer actively maintained, affected organizations should plan transitions away from this platform.
- CVE-2026-11520LOW 3.5
SourceCodester Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in the header.php file that allows authenticated users to inject malicious scripts through multiple parameters. An attacker with valid credentials can craft a specially crafted request to inject JavaScript that executes in the browsers of other users, potentially stealing session data or performing unauthorized actions on their behalf. Public exploit code is available, increasing the practical risk despite the low CVSS score.
- CVE-2026-11534LOW 3.5
A cross-site scripting (XSS) vulnerability exists in imvks786's student_management_system application. The flaw allows attackers to inject malicious scripts through the name, address, or fname parameters in the /add.php file. An attacker with authenticated access can craft a malicious request that, when clicked by another user, executes arbitrary JavaScript in that user's browser. The vulnerability is publicly known, and the development team has been notified but has not yet responded with a patch.
- CVE-2026-12047LOW 3.5
pgAdmin 4's cloud deployment wizard contains an HTML injection vulnerability in its AWS, Azure, and Google Cloud credential-verification endpoints. When pgAdmin receives an error message from a cloud provider's API (such as a rejected AWS access key), it forwards that error text directly into the web interface without removing HTML tags. An authenticated attacker can craft a malicious credential submission containing HTML/iframe code; when the cloud provider rejects it and echoes back the attacker's input in its error message, pgAdmin displays that message in the wizard—parsing it as HTML. This allows the attacker to inject an iframe pointing to a malicious site, redirecting the victim's browser away from pgAdmin. The vulnerability requires the attacker to be an authenticated pgAdmin user and requires user interaction (submitting the malicious credential). Redirecting another user would require an additional cross-site request-forgery vector.
- CVE-2026-12129LOW 3.5
CodeAstro Human Resource Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its Dashboard Interface. An attacker with login credentials can inject malicious scripts through the todo_data parameter in the /dashboard/add_tod endpoint. When another authenticated user views the affected page, the injected script executes in their browser, potentially allowing credential theft, session hijacking, or unauthorized actions performed on their behalf. The vulnerability requires user interaction—specifically, a victim must visit a page containing the malicious payload—and can only be exploited by someone with valid system access.
- CVE-2026-12130LOW 3.5
CVE-2026-12130 is a reflected cross-site scripting (XSS) vulnerability in CodeAstro Human Resource Management System version 1.0. An authenticated user can inject malicious scripts through the 'protitle' parameter on the Projects Management Page, which are then executed in the browsers of other users who view the injected content. The vulnerability requires user interaction (a victim must click a crafted link) and does not grant an attacker elevated privileges or direct data access, which limits its severity. However, it can be used to steal session cookies, redirect users, or perform actions on behalf of authenticated users within the HR system.
- CVE-2026-12812LOW 3.5
Radware Cyber Controller versions up to 10.11.0 contain an HTML injection vulnerability in the HTML Report Generation component. An authenticated attacker can inject malicious HTML code that will be rendered in reports viewed by other users. While the vulnerability requires an existing login and user interaction to exploit, the public disclosure and lack of vendor response increase risk. The flaw allows manipulation of report content and appearance but does not enable direct data theft or system crashes.
- CVE-2026-13504LOW 3.5
A cross-site scripting (XSS) vulnerability exists in code-projects Project Management System version 1.0 affecting the Mail Compose Page (/mail.php). An authenticated user can inject malicious scripts that execute in another user's browser when they interact with crafted email content. While the vulnerability requires login credentials and user interaction to exploit, public disclosure means attackers have access to exploitation methods.
- CVE-2026-13558LOW 3.5
CodeAstro Complaint Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its Report Handler component. An authenticated user can inject malicious script by manipulating the 'Report Title' field when adding a new report, which then executes in the browsers of other users viewing that report. Exploitation requires valid login credentials and user interaction (clicking a link or visiting a report page), but public exploit code is now available.
- CVE-2026-13570LOW 3.5
SourceCodester Inventory Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its user registration endpoint. An authenticated attacker can inject malicious code through the full_name parameter in the /api/users_handler.php file, which gets reflected in the application without proper sanitization. This allows the attacker to execute JavaScript in the browsers of other users who view the affected data, potentially stealing session tokens or performing actions on their behalf.
- CVE-2026-14752LOW 3.5
CVE-2026-14752 is a cross-site scripting (XSS) vulnerability in mjperpinosa stumasy, an open-source project using rolling releases. An authenticated attacker can manipulate the 'reference' argument in the add_definition function (found in application/PHP/objects/notes/add_into_dictionary.php) to inject malicious scripts. The vulnerability requires user interaction and authenticated access, limiting its immediate impact. Exploit code has been publicly disclosed, though the vendor has not yet responded to the early disclosure notification.
- CVE-2026-14791LOW 3.5
A cross-site scripting (XSS) vulnerability exists in Crater Invoice versions up to 6.0.6, specifically in how the application handles invoice notes. An authenticated user can inject malicious script code through the notes field, which gets executed in the browsers of other users who view that invoice. The vulnerability requires user interaction (clicking or viewing a crafted invoice) to trigger, but poses a real risk in multi-user invoicing environments where attackers may have legitimate access.
- CVE-2026-15311LOW 3.5
NousResearch hermes-agent contains a cross-site scripting (XSS) vulnerability in its Matrix Adapter component. When the MatrixAdapter processes Markdown-formatted messages and converts them to HTML, it fails to properly sanitize user-controlled input. An authenticated attacker can inject malicious scripts that execute in the context of another user's browser session, potentially stealing session tokens or performing actions on their behalf. The vulnerability requires the attacker to have valid credentials and user interaction (such as clicking a link), which limits its immediate threat scope. A fix is under review but not yet officially released.
- CVE-2026-3472LOW 3.5
Mattermost chat server has a vulnerability where AI bot result posts bypass markdown image rendering restrictions. An authenticated user can craft specially formatted content that, when viewed by a victim in their Mattermost client, triggers image requests to an attacker's server—potentially exfiltrating data about what the victim is viewing. The vulnerability requires a valid Mattermost account and user interaction (clicking or viewing the malicious post), limiting but not eliminating risk in collaborative environments.
- CVE-2026-35068LOW 3.5
Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection vulnerability that allows a low-privileged attacker with network access to the same segment to query the database directly and extract sensitive information. While the attacker needs valid credentials and local network access, the flaw bypasses input validation on database commands, potentially exposing configuration data, credentials, or operational metrics stored in PowerFlex deployments.
- CVE-2026-45159LOW 3.5
Nextcloud's end-to-end encrypted file drop feature contained a logic flaw that allowed a user with drop-link access to place files into other encrypted folders owned by the share recipient—without being able to read or modify existing files. The vulnerability affects multiple version lines and has been patched across all active branches.
- CVE-2026-45266LOW 3.5
A flaw in Nextcloud allows any authenticated user to remotely mute other participants' microphones during calls, but only when the deployment lacks a High-performance Backend configuration. This is a low-severity integrity issue that affects call participants' ability to communicate via audio.
- CVE-2026-48190LOW 3.5
OTRS has a permission-handling flaw in its External Interface and ConfigItem List module that allows authenticated customers to access Configuration Item (CI) information they shouldn't be able to see. The vulnerability only manifests when both CMDB is enabled and CustomerGroupSupport is configured, meaning organizations using default or simpler OTRS setups may not be affected. An attacker would need valid customer credentials and user interaction to exploit this issue.
- CVE-2026-48191LOW 3.5
A permissions bug in OTRS and STORM-powered OTRS allows authenticated users to discover metadata about configuration items (CIs), SLA levels, and services—such as how many are affected—without having actual access to view or modify them. An attacker needs valid login credentials and must interact with the Document Search Article Meta Filters modules to extract this information. While the exposure is limited to metadata disclosure rather than data access, it can provide reconnaissance value to an insider threat or compromised account holder.
- CVE-2026-48288LOW 3.5
Adobe Experience Manager contains a flaw in how it validates user input that can allow a logged-in attacker to bypass certain security controls and gain unauthorized write permissions. The attacker must trick a victim into visiting a malicious link or interacting with a compromised page, making this a lower-risk issue in practice. Affected versions include 6.5.24, LTS SP1, 2026.04 and earlier.
- CVE-2026-48289LOW 3.5
Adobe Experience Manager contains a vulnerability in how it validates user input that could allow a low-privileged attacker to bypass security controls and gain unauthorized write access to content. The attack requires the victim to visit a malicious link or interact with a compromised webpage, making it a practical but not trivial threat in environments where AEM is exposed to users. This is not currently listed as exploited in the wild.
- CVE-2026-52796LOW 3.5
Gogs, a self-hosted Git service, contains a denial-of-service vulnerability in how it renders issue index patterns. If an administrator configures an issue pattern with unmatched braces (an opening { without a closing }), the application crashes whenever a user views any page containing an issue reference like #1. This renders affected repositories inaccessible. The flaw stems from unsafe string handling in the pattern rendering code. Authenticated users with repository access can trigger the crash by simply viewing pages, though the vulnerability requires the misconfigured pattern to be in place first.
- CVE-2026-56330LOW 3.5
Capgo versions before 12.128.2 contain a flaw that allows authenticated users to manipulate billing-related URLs in ways that could redirect legitimate users to attacker-controlled websites. An attacker would need valid Capgo credentials and user interaction (a click on a malicious link) to exploit this. The vulnerability is rated LOW severity because it requires authentication and user action, though the phishing risk warrants attention in environments where billing workflows are exposed to untrusted users.
- CVE-2026-57522LOW 3.5
Bitwarden Server versions before 2026.5.0 allow authenticated users to inject malicious JSON data into event integration outputs by manipulating their own display name. When an organization has configured integrations (such as webhooks to SIEM, Slack, Teams, or Datadog) that include user information in the payload, an attacker can set their display name to contain JSON special characters. This causes the server to render those characters into the integration payload without properly escaping them, allowing the attacker to insert fake data fields that appear legitimate to downstream systems. The vulnerability requires an authenticated account and knowledge that event integrations are in use, limiting its scope to internal threat actors or compromised user accounts.
- CVE-2026-59213LOW 3.5
Open WebUI versions 0.6.27 through 0.9.x contain a caching flaw where permission-filtered lists of AI models meant to be personalized per user are incorrectly stored in a shared cache. This allows one authenticated user to see another user's available model list if they make a request during the same cache validity window. The vulnerability requires login access and has been fixed in version 0.10.0.
- CVE-2026-59791LOW 3.5
JetBrains YouTrack versions before 2026.2.17012 contain a CSS injection vulnerability in the Mermaid diagram rendering feature. An authenticated user can inject malicious CSS through diagram content, potentially allowing them to deface or manipulate how information appears to other users viewing the same diagrams. This is a low-severity issue because it requires authentication, user interaction, and affects only the presentation layer without compromising data confidentiality or system availability.
- CVE-2026-61492LOW 3.5
JetBrains YouTrack versions before 2026.2.17394 contain a stored cross-site scripting (XSS) vulnerability in article titles within digest emails. An authenticated attacker can inject malicious scripts into article titles that execute when other users view the digest email, potentially allowing credential theft, session hijacking, or malware distribution. The vulnerability requires user interaction (opening the email) and is confined to the email digest feature rather than the main application interface.
- CVE-2026-8801LOW 3.5
Progress MOVEit Transfer contains a path equivalence vulnerability in its file upload modules that could allow an authenticated user with limited privileges to modify files in unexpected ways. The vulnerability affects versions before 2025.0.8 and versions 2025.1.0 through 2025.1.3. While the technical impact is limited to file integrity (no data theft or availability loss), the issue highlights a logic flaw in how the application validates file paths during upload operations.
- CVE-2026-8981LOW 3.5
The Custom Block Builder WordPress plugin before version 4.3.0 fails to properly validate user permissions when handling block template code in certain scenarios. This allows site administrators—particularly on WordPress multisite networks or single-site installations with `DISALLOW_UNFILTERED_HTML` enabled—to inject malicious JavaScript into block templates. When visitors load pages containing these blocks, the injected code executes in their browsers, potentially compromising user sessions or stealing sensitive information.
- CVE-2026-9060LOW 3.5
The Store Locator WordPress plugin before version 1.6.6 contains a stored cross-site scripting (XSS) vulnerability in its admin settings. An administrator or similarly privileged user can inject malicious JavaScript into one of the plugin's settings, which is then executed when other high-privileged users (such as network super admins on multisite installations) visit the admin page. This bypasses WordPress's standard HTML filtering protections that normally prevent such attacks.
- CVE-2026-9061LOW 3.5
The Store Locator WordPress plugin versions prior to 1.6.9 contain a stored cross-site scripting (XSS) vulnerability in how it handles store logo metadata. An administrator or other high-privileged user can inject malicious scripts through the store logo field that will execute when viewed on the plugin's admin page. This remains exploitable even in environments where HTML filtering is normally disabled, such as WordPress multisite networks. The vulnerability requires administrator-level access to exploit, limiting its scope but still representing a control bypass concern in restricted environments.
- CVE-2026-9269LOW 3.5
Administrators and high-privilege users of the Secure Copy Content Protection and Content Locking WordPress plugin (versions before 5.1.5) can inject malicious scripts into the plugin's settings that persist in the database and execute in other users' browsers. This stored cross-site scripting (XSS) vulnerability bypasses WordPress's standard HTML filtering restrictions, even in restrictive multisite environments where the unfiltered_html capability is intentionally disabled.
- CVE-2026-9836LOW 3.5
IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain a vulnerability that allows authenticated users on the same network segment to access sensitive information they should not be able to view. The flaw requires an attacker to already have valid credentials and local network access, making opportunistic exploitation unlikely. This is a low-severity disclosure issue rather than a critical system compromise vector.
- CVE-2026-48940LOW 3.4
A K2 component vulnerability in Joomla allows authenticated users with Author-level permissions to inject unescaped JavaScript code into articles. When a user with "create item" rights submits an article and embeds malicious script tags in the `embedVideo` field, K2 stores and displays that code without sanitization, causing it to execute in visitors' browsers. This is a stored cross-site scripting (XSS) vulnerability that requires an attacker to already have article creation privileges—a relatively high bar that limits exposure in most Joomla deployments.
- CVE-2026-49370LOW 3.4
JetBrains YouTrack versions before 2026.1.13162 contain an information disclosure vulnerability affecting the fetchApp request handler. An authenticated user with high privileges can trigger unintended data exposure through a request that includes user interaction, though the scope of disclosed information is limited. This is a low-severity issue that requires administrative or privileged account access to exploit.
- CVE-2026-49381LOW 3.4
CVE-2026-49381 is a stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity's SAML login page that existed prior to version 2026.1. An attacker with high privileges could inject malicious scripts into the login interface, which would then execute in the browsers of users who interact with that page. The vulnerability requires user interaction to trigger and has limited scope, affecting only the confidentiality of information visible to the victim during their session.
- CVE-2026-9062LOW 3.4
The Store Locator WordPress plugin versions before 1.6.9 contain a path traversal vulnerability that allows site administrators to read sensitive files from the server, such as PHP configuration files containing database credentials and authentication keys. The vulnerability requires an authenticated administrator account to exploit, limiting its immediate risk to insider threats or compromised admin accounts.
- CVE-2025-15667LOW 3.3
GPAC, a popular multimedia framework used for MP4 file processing, contains a double-free memory vulnerability in its MP4Box component. The flaw exists in the `gf_isom_nalu_sample_rewrite` function and can be triggered by manipulating a specific argument (`nalu_out_bs`). An attacker with local access can craft a malicious MP4 file that, when processed by GPAC, causes the application to free the same memory region twice, potentially crashing the process. The vulnerability has been publicly disclosed, and a patch is available.
- CVE-2025-15668LOW 3.3
GPAC, an open-source multimedia framework widely used for MP4 processing and streaming, contains a heap-based buffer overflow vulnerability in its MP4Box component. The flaw resides in the sgpd_del_entry function, which fails to properly validate the data argument before using it in memory operations. An attacker with local access to a system running a vulnerable version of GPAC can trigger this overflow by providing malformed input to the MP4Box tool, potentially causing the application to crash or, in specific configurations, execute arbitrary code. A patch has been publicly released, and exploit code is known to exist in the wild.
- CVE-2025-48616LOW 3.3
CVE-2025-48616 is a logic error in Android's KeyguardViewMediator that allows a local attacker with basic user privileges to bypass lockdown mode when screen pinning is active, potentially exposing sensitive information on the device. The vulnerability requires no user interaction and poses a localized risk to data confidentiality on affected Android devices.
- CVE-2025-62338LOW 3.3
CVE-2025-62338 is a low-severity vulnerability in HCL BigFix Cloud Lifecycle Management caused by insufficient input validation. An authenticated local user can exploit this flaw to bypass security controls and access sensitive information they shouldn't have permission to view. The issue does not allow attackers to modify data or crash the system, only to read information they're not authorized to access.
- CVE-2026-0016LOW 3.3
A permissions validation flaw in Android's credential management system allows a local attacker with limited user privileges to read sensitive information across other user accounts without special permissions or user interaction. The vulnerability resides in how the system handles credential provider updates when services are removed, creating a bypass that exposes data intended to be isolated between users.
- CVE-2026-0050LOW 3.3
CVE-2026-0050 is a local information disclosure vulnerability in Android's Bluetooth adapter service. A malicious app with basic user-level permissions can bypass security checks in the handleBondStateChanged function to read sensitive Bluetooth-related information without requiring additional privileges or user interaction. The impact is limited to information disclosure; the attacker cannot modify data or crash the system.
- CVE-2026-0056LOW 3.3
CVE-2026-0056 is a memory safety issue in Android's ResourceTypes.cpp component where an incorrect bounds check allows a local process to read data outside intended memory boundaries. This flaw exposes sensitive information resident in adjacent memory to any app with basic local access—no special permissions, elevated privileges, or user interaction required. The vulnerability is classified as low severity due to its limited scope and local-only nature.
- CVE-2026-0057LOW 3.3
A permissions enforcement gap in Android's Contacts Provider allows local applications to view incoming call phone numbers and related metadata without explicit authorization. The issue requires local access to the device but no special privileges or user action during exploitation, making it a concern for applications that should be restricted from call monitoring data.
- CVE-2026-0134LOW 3.3
A logic error in Android's factory reset process allows sensitive data to persist on the device after a reset completes. An attacker with local access to the device can read this leftover information without needing special privileges or user interaction. While the exposure is limited to local information disclosure, the issue is particularly concerning because factory reset is a key data-wiping mechanism users rely on before selling, donating, or recycling devices.
- CVE-2026-0142LOW 3.3
CVE-2026-0142 is a local information disclosure vulnerability in Android's AVB (Android Verified Boot) RSA key parsing code. A local user can trigger an out-of-bounds memory read by supplying malformed key data, potentially exposing sensitive information from adjacent memory. The flaw requires only local access and user-level privileges—no special permissions or user interaction is required to exploit it.
- CVE-2026-0145LOW 3.3
CVE-2026-0145 is a permission bypass vulnerability in Android's KeyMint component that allows a local attacker with basic user privileges to read sensitive information without needing to interact with the system or escalate their access level. The flaw stems from a logic error in how permissions are validated, creating an unintended pathway for unauthorized data access.
- CVE-2026-0158LOW 3.3
A flaw in Android's Camera application allows a local user to view photos they shouldn't be able to access. The vulnerability stems from missing permission validation when accessing photo data. Since no special privileges or user interaction are required beyond initial device access, any app or user account on the device could potentially read private photos. The actual impact is limited to unauthorized photo disclosure—the vulnerability doesn't enable device compromise or broader system damage.
- CVE-2026-10197LOW 3.3
Assimp, a widely-used open-source 3D model import library, contains a flaw in its glTF2 file handler that can cause the application to crash when processing maliciously crafted glTF2 files with embedded textures. An attacker with local file system access can trigger a null pointer dereference by supplying a crafted glTF2 file, leading to denial of service. The vulnerability affects versions up to and including 6.0.4. A fix exists in pending pull request form but has not yet been merged into a stable release.
- CVE-2026-10198LOW 3.3
Assimp, a popular open-source 3D model import library, contains a flaw in its glTF file import handler that can cause the application to crash. The vulnerability stems from improper handling of certain glTF mesh data, leading to a null pointer dereference when the ImportMeshes function processes malformed or specially crafted files. An attacker with local access to a system running a vulnerable version of Assimp could trigger this crash, resulting in denial of service. The issue affects Assimp versions up to and including 6.0.4.
- CVE-2026-10199LOW 3.3
Assimp, a popular 3D asset library, contains a null pointer dereference vulnerability in its glTF2 parsing code. An attacker with local access can craft a malicious glTF2 file that triggers a crash when processed, causing a denial of service. The vulnerability affects Assimp versions up to 6.0.4 and has been publicly disclosed, though it requires local interaction and low privileges to exploit.
- CVE-2026-10201LOW 3.3
CVE-2026-10201 is a divide-by-zero flaw in Assimp (Asset Importer Library), a widely-used 3D model processing library. The defect exists in the UV Channel Handler component, specifically within the FBXExporter::WriteObjects function in FBXExporter.cpp. When a user with local access supplies specially crafted input, the vulnerability triggers a division-by-zero error that crashes the application. Because this is a local-only attack requiring user-level privileges and the impact is availability-focused (denial of service via crash), the risk is classified as low. However, the fact that proof-of-concept code has been publicly released means defenders should not assume this will remain a theoretical concern.
- CVE-2026-10233LOW 3.3
Assimp, a popular open-source 3D model importing library, contains an out-of-bounds read vulnerability in its Half-Life 1 MDL file loader. When processing specially crafted MDL files, the vulnerability allows an attacker with local access to read memory outside intended boundaries. While the issue has been publicly disclosed, the impact is limited to information disclosure with no ability to modify or crash systems. This vulnerability requires local file system access and authenticated user privileges to trigger.
- CVE-2026-10267LOW 3.3
A flaw in the Janet programming language (version 1.41.0 and earlier) allows a local user to read memory beyond intended boundaries in the debug frame handling code. The vulnerability requires local system access and valid user credentials to exploit, but poses a confidentiality risk by enabling unauthorized disclosure of sensitive data in memory.
- CVE-2026-10268LOW 3.3
A vulnerability exists in Janet language versions up to 1.41.0 that allows an integer overflow when processing serialized fiber data. An attacker with local system access can exploit this condition to cause a denial of service by crashing the affected application. The vulnerability is not critical but represents a real risk in environments where untrusted users have local access to systems running vulnerable Janet versions.
- CVE-2026-10295LOW 3.3
CVE-2026-10295 is a low-severity denial-of-service vulnerability in SourceCodester Customer Review App version 1.0. By manipulating the 'name' or 'comment' parameters in the review submission functions, an attacker with local access can crash or degrade the application's availability. While an exploit has been published, the attack surface is limited because local authentication is required—this is not a remote vulnerability that can be exploited from the internet.
- CVE-2026-10298LOW 3.3
A null pointer dereference vulnerability exists in whisper.cpp versions up to 1.8.2, specifically in the model loading function. An attacker with local system access can trigger this flaw to cause the application to crash or become unavailable. The vulnerability requires user privileges to exploit and does not directly compromise data confidentiality or integrity. Public exploit code is available, though the impact remains limited to denial of service on the affected system.
- CVE-2026-10528LOW 3.3
Orthanc DICOM Server versions up to 1.12.11 contain a stack-based buffer overflow vulnerability in the DCMTK parser component. The flaw exists in the DcmItem::read function and can be triggered through malicious DICOM file manipulation. An attacker with local system access can exploit this to cause a denial of service condition. The vulnerability has been publicly disclosed with working exploit code available.
- CVE-2026-10722LOW 3.3
A local integer overflow vulnerability exists in Cilium eBPF's BTF (BPF Type Format) loading functionality. An attacker with local system access can manipulate offset parameters during eBPF collection loading, causing the application to miscalculate memory boundaries. While the impact is limited to denial of service on the affected system, the public disclosure means exploitation tools may become available. This is a localized threat requiring prior system access but warrants patching to maintain system stability.
- CVE-2026-11312LOW 3.3
A flaw in ByteDance's InfiniStore library (versions up to 0.2.33) allows a local user to trigger inefficient algorithmic behavior in the key-value map purge function. An attacker with local access can manipulate input to the purge_kv_map routine, causing the function to consume excessive CPU or processing time. The vulnerability requires local system access and valid user privileges, limiting its scope, but public exploit code now exists.
- CVE-2026-11459LOW 3.3
SecureAge CatchPulse versions up to 10.9.3 contain a vulnerability in the saappctl.sys driver that can leak sensitive information to authenticated local users. An attacker with a valid local account on the affected system can trigger the IOCTL handler to access data they shouldn't normally see. The vulnerability has been publicly disclosed and active exploitation is possible, though it requires legitimate access to the target machine.
- CVE-2026-11478LOW 3.3
CVE-2026-11478 is a denial-of-service vulnerability in the kokke tiny-regex-c library that allows a local attacker to trigger inefficient regular expression processing through the matchstar function. An attacker with local access and basic privileges can craft a malicious regex pattern that causes excessive computation, potentially slowing or stalling applications that parse untrusted regex inputs. The severity is low because exploitation requires local execution and user-level permissions, but the published exploit code means the attack method is already in the wild.
- CVE-2026-11792LOW 3.3
A memory corruption flaw exists in 389 Directory Server's audit logging feature. When audit logging is enabled and certain password storage conditions are met, the server can write more data than a buffer can hold, corrupting memory and producing garbled audit logs. The vulnerability requires non-standard configuration or a compromised replication partner to trigger, which limits real-world exposure.
- CVE-2026-12823LOW 3.3
A permissions misconfiguration vulnerability has been discovered in Browserbase Skills (versions up to 20260526) affecting the Autobrowse Trace Artifact Handler component. The flaw results in incorrect default access controls that could allow a local user to read sensitive information. This is a low-severity issue requiring local system access to exploit, and while proof-of-concept code has been publicly released, the practical risk remains limited due to its local-only attack vector and information-disclosure nature.
- CVE-2026-13523LOW 3.3
GPAC versions up to 26.02.0 contain a flaw in how the ISOBMFF (ISO Base Media File Format) parser handles compressed data during file processing. An attacker with local access to a system running GPAC can craft a malicious media file that triggers excessive data decompression, potentially causing the application to become unavailable or consume excessive system resources. The vulnerability requires direct access to the affected system and local execution context, which significantly limits its real-world attack surface.
- CVE-2026-13573LOW 3.3
A stack-based buffer overflow vulnerability has been reported in LLVM's StringMap insertion function within the ValueSymbolTable module. The issue affects LLVM versions up to 22.1.6 and requires local access to exploit. Notably, the LLVM project has stated this behavior falls outside their documented security scope and is not considered a security vulnerability by the maintainers. Exploit code has been publicly disclosed, though verification of the vulnerability's actual exploitability remains uncertain.
- CVE-2026-13574LOW 3.3
CVE-2026-13574 affects LLVM versions up to 22.1.6 and involves a heap-based buffer overflow in the bitcode file handler component. A local attacker with user-level privileges could trigger a denial of service condition by manipulating the GCRelocateInst::getBasePtr function. Notably, the LLVM project has disputed the security classification of this issue, stating that the reported behavior falls outside its documented security scope. Despite public disclosure, exploitation requires local access and does not compromise confidentiality or integrity.
- CVE-2026-13942LOW 3.3
A vulnerability in Google Chrome's video capture implementation on ChromeOS allows a local attacker to create fake UI elements through a specially crafted web page. The attacker must already have local access to the device and the user must interact with the malicious page, but the attack only affects the visual presentation of the interface—it cannot steal data or crash the system.
- CVE-2026-13955LOW 3.3
Google Chrome on Android contains a UI spoofing vulnerability in its CustomTabs feature that could allow a local attacker to deceive users by manipulating the app's visual appearance. The vulnerability stems from insufficient validation when processing untrusted input from malicious files. An attacker would need local access to the device and user interaction (such as opening a file) to exploit it. The attack surface is limited because it requires both proximity and user action, and the impact is restricted to visual deception rather than data theft or system compromise.
- CVE-2026-14650LOW 3.3
A denial-of-service vulnerability has been identified in connorskees grass, a Sass compiler, affecting versions up to 0.13.4. The flaw exists in the UTF-8 character handling component and can be triggered through a local attack to cause the compiler to hang or consume excessive resources. While an exploit has been published, the practical impact is limited because the vulnerability requires local code execution and aligns with inherent design characteristics of Sass compilation where exponential behavior is expected and acceptable.
- CVE-2026-14651LOW 3.3
A denial of service vulnerability exists in the grass Sass compiler (versions up to 0.13.4) affecting the selector extension functionality. An attacker with local access can craft malicious Sass input that causes excessive compilation time, potentially consuming system resources. The vendor has clarified that the vulnerability description conflates expected algorithmic behavior with an actual flaw—the @extend mechanism is inherently exponential by design, and DoS conditions via recursive constructs are a known characteristic of Sass compilers rather than a security defect.
- CVE-2026-14683LOW 3.3
HdrHistogram, a popular latency histogram library, contains a vulnerability in how it processes compressed binary data. An attacker with local access could supply specially crafted compressed data that causes the application to allocate excessive memory, potentially leading to a denial of service. The vulnerability exists in versions up to 2.2.2 and requires local system access to exploit. The security community remains divided on whether this truly constitutes a security boundary crossing, given the prerequisites involved.
- CVE-2026-14684LOW 3.3
HdrHistogram, a Java library used for recording and analyzing latency distributions, contains a flaw in how it decodes serialized histogram data from byte buffers. When processing the numberOfSignificantValueDigits parameter during deserialization, the library can allocate excessive memory without proper bounds checking. This is a local-only vulnerability—an attacker must already have access to run code on the affected system. While proof-of-concept code has been published, the security community disputes whether this crosses a meaningful security boundary, since the preconditions for exploitation are restrictive.
- CVE-2026-14685LOW 3.3
HdrHistogram, a latency histogram library, contains a vulnerability in its AbstractHistogram component where the recordValueWithCount method improperly handles the Count argument, leading to state corruption. The flaw is local-only, requires authenticated user privileges, and has been publicly disclosed. Importantly, the security community disputes whether this crosses meaningful security boundaries, given the prerequisites needed for exploitation.
- CVE-2026-14686LOW 3.3
HdrHistogram, a Java library for recording and analyzing latency distributions, contains a flaw in its range-checking logic for the DoubleHistogram component. When recording values, the library performs an incorrect comparison that could allow a local user to bypass validation checks. The vulnerability requires local system access and has limited security impact, as it does not enable data exfiltration or system unavailability—only the integrity of recorded histogram data could be affected. The security community has disputed whether this truly crosses a meaningful security boundary, and exploit details are now public.
- CVE-2026-14699LOW 3.3
CVE-2026-14699 is a local symlink-following vulnerability in markdownify-mcp, a Markdown conversion tool. An attacker with local access and low-level privileges can manipulate file paths to cause the application to follow symbolic links, potentially reading files outside the intended directory. The risk is contained because exploitation requires direct local access and low-privilege user status.
- CVE-2026-14758LOW 3.3
A bug in radare2 (an open-source reverse-engineering framework) allows a local user with basic privileges to trigger an integer overflow when the hexpairs parser processes specially crafted input in the opcode analysis command. This causes the application to crash. An attacker would need direct access to a system running radare2 and the ability to execute commands locally.
- CVE-2026-14759LOW 3.3
A heap-based buffer overflow vulnerability exists in radare2, a popular reverse-engineering framework, affecting versions up to 6.1.6. The flaw is in the Java class file parser's line number table handler and can be triggered through a specially crafted Java binary. An attacker with local system access can exploit this to crash the application or potentially execute code. Public exploit code is available, elevating operational risk for users who process untrusted Java artifacts.
- CVE-2026-14760LOW 3.3
A use-after-free vulnerability has been discovered in radare2, a popular reverse-engineering framework. The flaw exists in the regprofile handler component and can be triggered by local attackers with low privileges, leading to an application crash or potential memory corruption. While a patch has been released, the vulnerability is not currently listed as exploited in the wild by known ransomware groups or government-backed actors.
- CVE-2026-14761LOW 3.3
A flaw in radare2's string handling functions (r_str_ndup and r_str_append) allows an attacker with local access to cause the application to crash by triggering an integer overflow. The vulnerability affects radare2 up to version 6.1.6. While an exploit has been publicly disclosed, the impact is limited to denial of service—no data theft or privilege escalation is possible from this flaw alone.
- CVE-2026-14786LOW 3.3
A flaw in radare2, a popular reverse engineering framework, allows an authenticated local attacker to trigger an integer overflow through the string handling function. While the vulnerability requires local access and legitimate user privileges, the public release of exploit code means the risk of opportunistic abuse increases. The impact is denial of service—the affected process can crash—but not data theft or privilege escalation.
- CVE-2026-14787LOW 3.3
Radare2, a popular open-source reverse-engineering framework, contains an integer overflow vulnerability in its print command handler that can be triggered by a local user. The flaw affects versions up to 6.1.6 and can cause the application to crash or become unstable. While a public exploit exists, the attack requires local system access and does not enable privilege escalation or data theft. The vendor has released a patch that should be applied to restore stability.
- CVE-2026-14788LOW 3.3
A use-after-free vulnerability exists in Radare2, a widely-used reverse engineering and binary analysis framework. The flaw is located in the binary loading function and can be triggered by a local attacker with basic user privileges. While the vulnerability has been publicly disclosed, its low severity rating reflects limited direct impact—the primary consequence is denial of service through application crash. Organizations using Radare2 in production or security workflows should apply the available patch, particularly if the tool processes untrusted binaries.