Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11549 | MEDIUM | 6.5 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. | Sep 18, 2026 |
| CVE-2026-11548 | MEDIUM | 4.8 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | Sep 18, 2026 |
| CVE-2026-11545 | LOW | 3.7 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. | Sep 18, 2026 |
| CVE-2026-11540 | MEDIUM | 5.3 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | Sep 18, 2026 |
| CVE-2026-11539 | MEDIUM | 5.3 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. | Sep 18, 2026 |
| CVE-2017-20284 | HIGH | 7.5 | Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative … | Sep 18, 2026 |
| CVE-2026-93854 | UNKNOWN | — | In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). … | Sep 18, 2026 |
| CVE-2026-93852 | UNKNOWN | — | In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. … | Sep 18, 2026 |
| CVE-2026-93650 | LOW | 3.7 | A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to … | Sep 18, 2026 |
| CVE-2026-75894 | UNKNOWN | — | In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash … | Sep 18, 2026 |
| CVE-2026-75893 | UNKNOWN | — | In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths. | Sep 18, 2026 |
| CVE-2026-75892 | UNKNOWN | — | In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption. | Sep 18, 2026 |
| CVE-2026-11538 | LOW | 3.7 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. | Sep 18, 2026 |
| CVE-2023-54399 | CRITICAL | 9.8 | Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without … | Sep 18, 2026 |
| CVE-2021-48008 | HIGH | 7.5 | Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the … | Sep 18, 2026 |
| CVE-2019-25776 | HIGH | 7.5 | Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET … | Sep 18, 2026 |
| CVE-2026-93764 | MEDIUM | 6.5 | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore … | Sep 18, 2026 |
| CVE-2026-93763 | MEDIUM | 6.5 | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written … | Sep 18, 2026 |
| CVE-2026-93762 | CRITICAL | 9.8 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain … | Sep 18, 2026 |
| CVE-2026-93761 | HIGH | 7.5 | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing … | Sep 18, 2026 |
| CVE-2026-93760 | HIGH | 8.2 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an … | Sep 18, 2026 |
| CVE-2026-93759 | HIGH | 8.6 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. … | Sep 18, 2026 |
| CVE-2026-93753 | HIGH | 7.5 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can … | Sep 18, 2026 |
| CVE-2026-93752 | HIGH | 7.5 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a … | Sep 18, 2026 |
| CVE-2026-93751 | MEDIUM | 6.5 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded … | Sep 18, 2026 |