Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54755
Total
4323
Critical
16270
High
16026
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81545 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … | Sep 24, 2026 |
| CVE-2026-81539 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … | Sep 24, 2026 |
| CVE-2026-77874 | HIGH | 8.6 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted … | Sep 24, 2026 |
| CVE-2026-77825 | MEDIUM | 4.9 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses … | Sep 24, 2026 |
| CVE-2026-77707 | MEDIUM | 5.9 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before … | Sep 24, 2026 |
| CVE-2026-77703 | MEDIUM | 5.9 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from … | Sep 24, 2026 |
| CVE-2026-73064 | LOW | 2.9 | In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes … | Sep 24, 2026 |
| CVE-2026-6544 | MEDIUM | 6.2 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and … | Sep 24, 2026 |
| CVE-2026-65422 | MEDIUM | 6.5 | A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video … | Sep 24, 2026 |
| CVE-2026-58008 | HIGH | 8.1 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … | Sep 24, 2026 |
| CVE-2026-58007 | HIGH | 8.1 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … | Sep 24, 2026 |
| CVE-2026-58006 | HIGH | 8.1 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … | Sep 24, 2026 |
| CVE-2026-58005 | HIGH | 8.1 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | Sep 24, 2026 |
| CVE-2026-58004 | HIGH | 8.1 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | Sep 24, 2026 |
| CVE-2026-56736 | HIGH | 8.2 | phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged … | Sep 24, 2026 |
| CVE-2026-52001 | UNKNOWN | — | An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts | Sep 24, 2026 |
| CVE-2026-51997 | UNKNOWN | — | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions | Sep 24, 2026 |
| CVE-2026-51996 | UNKNOWN | — | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function | Sep 24, 2026 |
| CVE-2026-51995 | HIGH | 7.5 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components | Sep 24, 2026 |
| CVE-2026-51994 | UNKNOWN | — | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header | Sep 24, 2026 |
| CVE-2026-19492 | LOW | 3.2 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker … | Sep 24, 2026 |
| CVE-2026-18870 | MEDIUM | 4.3 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information … | Sep 24, 2026 |
| CVE-2026-13467 | HIGH | 8.1 | Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | Sep 24, 2026 |
| CVE-2026-13466 | HIGH | 8.1 | Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | Sep 24, 2026 |
| CVE-2026-13465 | HIGH | 8.1 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … | Sep 24, 2026 |