Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-17465 | MEDIUM | 6.5 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits. | Sep 22, 2026 |
| CVE-2026-17102 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … | Sep 22, 2026 |
| CVE-2026-16672 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … | Sep 22, 2026 |
| CVE-2026-16469 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special … | Sep 22, 2026 |
| CVE-2026-16468 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection. | Sep 22, 2026 |
| CVE-2026-16426 | MEDIUM | 6.5 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, … | Sep 22, 2026 |
| CVE-2026-16346 | CRITICAL | 9.9 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … | Sep 22, 2026 |
| CVE-2026-15915 | MEDIUM | 6.2 | IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images. | Sep 22, 2026 |
| CVE-2025-36084 | MEDIUM | 5.9 | IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Sep 22, 2026 |
| CVE-2025-12767 | MEDIUM | 5.3 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause … | Sep 22, 2026 |
| CVE-2026-96269 | UNKNOWN | — | GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. … | Sep 22, 2026 |
| CVE-2026-96260 | MEDIUM | 6.5 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation … | Sep 22, 2026 |
| CVE-2026-96259 | MEDIUM | 5.5 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which … | Sep 22, 2026 |
| CVE-2026-95815 | MEDIUM | 6.3 | OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives … | Sep 22, 2026 |
| CVE-2026-95814 | HIGH | 8.1 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment … | Sep 22, 2026 |
| CVE-2026-95813 | MEDIUM | 6.1 | e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation … | Sep 22, 2026 |
| CVE-2026-95812 | MEDIUM | 6.1 | ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. … | Sep 22, 2026 |
| CVE-2026-94450 | HIGH | 7.5 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service … | Sep 22, 2026 |
| CVE-2026-91018 | HIGH | 8.8 | lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim … | Sep 22, 2026 |
| CVE-2026-89019 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 22, 2026 |
| CVE-2026-88020 | MEDIUM | 6.1 | Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the … | Sep 22, 2026 |
| CVE-2026-77987 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of … | Sep 22, 2026 |
| CVE-2026-77912 | UNKNOWN | — | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown … | Sep 22, 2026 |
| CVE-2026-77426 | UNKNOWN | — | Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by … | Sep 22, 2026 |
| CVE-2026-77425 | MEDIUM | 4.3 | Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and updateSortOrder without verifying that the IDs … | Sep 22, 2026 |