Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55204
Total
4355
Critical
16406
High
16086
Medium
CVE ID Severity Score Description Published
CVE-2026-17465 MEDIUM 6.5 IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits. Sep 22, 2026
CVE-2026-17102 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … Sep 22, 2026
CVE-2026-16672 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … Sep 22, 2026
CVE-2026-16469 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special … Sep 22, 2026
CVE-2026-16468 HIGH 8.8 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection. Sep 22, 2026
CVE-2026-16426 MEDIUM 6.5 IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, … Sep 22, 2026
CVE-2026-16346 CRITICAL 9.9 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … Sep 22, 2026
CVE-2026-15915 MEDIUM 6.2 IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images. Sep 22, 2026
CVE-2025-36084 MEDIUM 5.9 IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. Sep 22, 2026
CVE-2025-12767 MEDIUM 5.3 IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause … Sep 22, 2026
CVE-2026-96269 UNKNOWN — GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. … Sep 22, 2026
CVE-2026-96260 MEDIUM 6.5 Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation … Sep 22, 2026
CVE-2026-96259 MEDIUM 5.5 Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which … Sep 22, 2026
CVE-2026-95815 MEDIUM 6.3 OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives … Sep 22, 2026
CVE-2026-95814 HIGH 8.1 Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment … Sep 22, 2026
CVE-2026-95813 MEDIUM 6.1 e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation … Sep 22, 2026
CVE-2026-95812 MEDIUM 6.1 ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. … Sep 22, 2026
CVE-2026-94450 HIGH 7.5 Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service … Sep 22, 2026
CVE-2026-91018 HIGH 8.8 lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim … Sep 22, 2026
CVE-2026-89019 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 22, 2026
CVE-2026-88020 MEDIUM 6.1 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the … Sep 22, 2026
CVE-2026-77987 UNKNOWN — A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of … Sep 22, 2026
CVE-2026-77912 UNKNOWN — A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown … Sep 22, 2026
CVE-2026-77426 UNKNOWN — Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by … Sep 22, 2026
CVE-2026-77425 MEDIUM 4.3 Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and updateSortOrder without verifying that the IDs … Sep 22, 2026