Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-11725 HIGH 8.8 IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ … Sep 18, 2026
CVE-2026-11722 MEDIUM 4.8 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. Sep 18, 2026
CVE-2026-11716 HIGH 7.5 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during … Sep 18, 2026
CVE-2026-11711 MEDIUM 6.5 IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. Sep 18, 2026
CVE-2026-11710 MEDIUM 6.5 IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. Sep 18, 2026
CVE-2026-11549 MEDIUM 6.5 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. Sep 18, 2026
CVE-2026-11548 MEDIUM 4.8 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. Sep 18, 2026
CVE-2026-11545 LOW 3.7 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. Sep 18, 2026
CVE-2026-11540 MEDIUM 5.3 IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. Sep 18, 2026
CVE-2026-11539 MEDIUM 5.3 IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. Sep 18, 2026
CVE-2017-20284 HIGH 7.5 Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative … Sep 18, 2026
CVE-2026-93854 UNKNOWN — In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). … Sep 18, 2026
CVE-2026-93852 UNKNOWN — In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. … Sep 18, 2026
CVE-2026-93650 LOW 3.7 A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to … Sep 18, 2026
CVE-2026-75894 UNKNOWN — In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash … Sep 18, 2026
CVE-2026-75893 UNKNOWN — In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths. Sep 18, 2026
CVE-2026-75892 UNKNOWN — In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption. Sep 18, 2026
CVE-2026-11538 LOW 3.7 IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. Sep 18, 2026
CVE-2023-54399 CRITICAL 9.8 Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without … Sep 18, 2026
CVE-2021-48008 HIGH 7.5 Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the … Sep 18, 2026
CVE-2019-25776 HIGH 7.5 Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET … Sep 18, 2026
CVE-2026-93764 MEDIUM 6.5 Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore … Sep 18, 2026
CVE-2026-93763 MEDIUM 6.5 A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written … Sep 18, 2026
CVE-2026-93762 CRITICAL 9.8 Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain … Sep 18, 2026
CVE-2026-93761 HIGH 7.5 An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing … Sep 18, 2026