Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-1037 | MEDIUM | 6.1 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an … | Sep 18, 2026 |
| CVE-2026-1031 | MEDIUM | 6.1 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an … | Sep 18, 2026 |
| CVE-2026-1030 | MEDIUM | 4.3 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about … | Sep 18, 2026 |
| CVE-2026-1029 | MEDIUM | 5.4 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users … | Sep 18, 2026 |
| CVE-2026-1025 | MEDIUM | 6.1 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users … | Sep 18, 2026 |
| CVE-2026-11537 | MEDIUM | 4.3 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | Sep 18, 2026 |
| CVE-2026-11381 | HIGH | 8.8 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution … | Sep 18, 2026 |
| CVE-2026-11378 | HIGH | 8.8 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution … | Sep 18, 2026 |
| CVE-2026-11375 | HIGH | 8.8 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when … | Sep 18, 2026 |
| CVE-2026-10858 | CRITICAL | 9.9 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due … | Sep 18, 2026 |
| CVE-2026-10853 | HIGH | 7.5 | IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation … | Sep 18, 2026 |
| CVE-2026-10841 | MEDIUM | 4.2 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. | Sep 18, 2026 |
| CVE-2026-10751 | HIGH | 7.5 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass … | Sep 18, 2026 |
| CVE-2026-10747 | CRITICAL | 10.0 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow … | Sep 18, 2026 |
| CVE-2026-10744 | HIGH | 7.5 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to … | Sep 18, 2026 |
| CVE-2026-10575 | HIGH | 8.8 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing … | Sep 18, 2026 |
| CVE-2026-10030 | HIGH | 7.1 | IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks. | Sep 18, 2026 |
| CVE-2026-10027 | HIGH | 8.1 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed … | Sep 18, 2026 |
| CVE-2025-61682 | HIGH | 8.6 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and … | Sep 18, 2026 |
| CVE-2025-53837 | CRITICAL | 9.9 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior … | Sep 18, 2026 |
| CVE-2025-36421 | MEDIUM | 5.9 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information … | Sep 18, 2026 |
| CVE-2025-36178 | MEDIUM | 5.4 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of … | Sep 18, 2026 |
| CVE-2025-36147 | MEDIUM | 6.1 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed … | Sep 18, 2026 |
| CVE-2025-36076 | MEDIUM | 4.3 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user … | Sep 18, 2026 |
| CVE-2025-36045 | MEDIUM | 4.3 | IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of … | Sep 18, 2026 |