Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56172
Total
4442
Critical
16641
High
16421
Medium
CVE ID Severity Score Description Published
CVE-2026-11549 MEDIUM 6.5 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. Sep 18, 2026
CVE-2026-11548 MEDIUM 4.8 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. Sep 18, 2026
CVE-2026-11545 LOW 3.7 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. Sep 18, 2026
CVE-2026-11540 MEDIUM 5.3 IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. Sep 18, 2026
CVE-2026-11539 MEDIUM 5.3 IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. Sep 18, 2026
CVE-2017-20284 HIGH 7.5 Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative … Sep 18, 2026
CVE-2026-93854 UNKNOWN — In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). … Sep 18, 2026
CVE-2026-93852 UNKNOWN — In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. … Sep 18, 2026
CVE-2026-93650 LOW 3.7 A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to … Sep 18, 2026
CVE-2026-75894 UNKNOWN — In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash … Sep 18, 2026
CVE-2026-75893 UNKNOWN — In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths. Sep 18, 2026
CVE-2026-75892 UNKNOWN — In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption. Sep 18, 2026
CVE-2026-11538 LOW 3.7 IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. Sep 18, 2026
CVE-2023-54399 CRITICAL 9.8 Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without … Sep 18, 2026
CVE-2021-48008 HIGH 7.5 Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the … Sep 18, 2026
CVE-2019-25776 HIGH 7.5 Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET … Sep 18, 2026
CVE-2026-93764 MEDIUM 6.5 Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore … Sep 18, 2026
CVE-2026-93763 MEDIUM 6.5 A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written … Sep 18, 2026
CVE-2026-93762 CRITICAL 9.8 Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain … Sep 18, 2026
CVE-2026-93761 HIGH 7.5 An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing … Sep 18, 2026
CVE-2026-93760 HIGH 8.2 Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an … Sep 18, 2026
CVE-2026-93759 HIGH 8.6 Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. … Sep 18, 2026
CVE-2026-93753 HIGH 7.5 deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can … Sep 18, 2026
CVE-2026-93752 HIGH 7.5 CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a … Sep 18, 2026
CVE-2026-93751 MEDIUM 6.5 uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded … Sep 18, 2026