Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54949
Total
4343
Critical
16375
High
16061
Medium
CVE ID Severity Score Description Published
CVE-2026-80425 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … Sep 23, 2026
CVE-2026-80412 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property … Sep 23, 2026
CVE-2026-80379 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … Sep 23, 2026
CVE-2026-75886 HIGH 7.2 A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of … Sep 23, 2026
CVE-2026-6935 HIGH 7.8 IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker … Sep 23, 2026
CVE-2026-6928 CRITICAL 9.8 IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input … Sep 23, 2026
CVE-2026-6925 MEDIUM 5.3 IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request … Sep 23, 2026
CVE-2026-6794 HIGH 7.8 IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to … Sep 23, 2026
CVE-2026-6730 CRITICAL 9.8 IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute … Sep 23, 2026
CVE-2026-6721 CRITICAL 9.8 IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command … Sep 23, 2026
CVE-2026-6718 MEDIUM 6.2 IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files. Sep 23, 2026
CVE-2026-67405 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler … Sep 23, 2026
CVE-2026-67404 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back … Sep 23, 2026
CVE-2026-67240 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ -> ., then compiles ^...$ … Sep 23, 2026
CVE-2026-67235 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation … Sep 23, 2026
CVE-2026-67232 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress … Sep 23, 2026
CVE-2026-67231 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, … Sep 23, 2026
CVE-2026-67229 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_vhost/2 calls rabbit_data_coercion:atomize_keys/1 (the unsafe variant using binary_to_atom) on … Sep 23, 2026
CVE-2026-67228 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The runtime-parameters lookup path coerces the URL :component segment to an atom … Sep 23, 2026
CVE-2026-67224 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The trace consumer constructs the output path as filename:join(TraceDir, … Sep 23, 2026
CVE-2026-67221 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its … Sep 23, 2026
CVE-2026-67220 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0, When a binding is created on an x-jms-topic exchange, add_binding/3 … Sep 23, 2026
CVE-2026-67219 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3 parses the routing key as an integer weight … Sep 23, 2026
CVE-2026-67218 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at line 56 calls rabbit_stream_manager:create_super_stream/... directly after is_authorized (which … Sep 23, 2026
CVE-2026-66080 UNKNOWN — RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least … Sep 23, 2026