LOW severity

13 records · 4 with a public proof-of-concept

CVSS 0.1–3.9. Limited impact, or exploitation requires improbable conditions.

  1. LOW 3.9CVE-2026-8029

    The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.9CVE-2026-16791

    A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed wit

    AI risk analysis on Exploit-DB.ai →

  3. LOW 3.8CVE-2026-12730

    IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostn

    business automation workflow

    AI risk analysis on Exploit-DB.ai →

  4. LOW 3.7CVE-2026-16993

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (suc

    AI risk analysis on Exploit-DB.ai →

  5. LOW 3.7CVE-2026-11366

    The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empt

    AI risk analysis on Exploit-DB.ai →

  6. LOW 3.5CVE-2025-15677

    The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when

    AI risk analysis on Exploit-DB.ai →

  7. LOW 3.5CVE-2026-16068

    The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary Jav

    AI risk analysis on Exploit-DB.ai →

  8. LOW 3.3CVE-2026-18852public PoC

    A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to

    AI risk analysis on Exploit-DB.ai →

  9. LOW 3.3CVE-2026-18790public PoC

    A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequ

    AI risk analysis on Exploit-DB.ai →

  10. LOW 3.1CVE-2026-70483public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who kn

    AI risk analysis on Exploit-DB.ai →

  11. LOW 2.7CVE-2026-16746

    The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

    AI risk analysis on Exploit-DB.ai →

  12. LOW 2.7CVE-2026-16070

    The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with

    AI risk analysis on Exploit-DB.ai →

  13. LOW 2.2CVE-2026-18817public PoC

    A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing

    AI risk analysis on Exploit-DB.ai →