Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-33147 | MEDIUM | 5.9 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused … | Sep 18, 2026 |
| CVE-2025-33141 | MEDIUM | 6.5 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions … | Sep 18, 2026 |
| CVE-2025-15399 | CRITICAL | 10.0 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow … | Sep 18, 2026 |
| CVE-2025-14754 | HIGH | 8.8 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation … | Sep 18, 2026 |
| CVE-2025-14753 | HIGH | 7.5 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL … | Sep 18, 2026 |
| CVE-2026-93685 | MEDIUM | 5.4 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework … | Sep 18, 2026 |
| CVE-2026-93676 | LOW | 3.2 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the … | Sep 18, 2026 |
| CVE-2026-93660 | MEDIUM | 6.5 | SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can … | Sep 18, 2026 |
| CVE-2026-93659 | HIGH | 8.7 | Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in … | Sep 18, 2026 |
| CVE-2026-93658 | HIGH | 7.0 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned … | Sep 18, 2026 |
| CVE-2026-93657 | HIGH | 7.5 | hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful … | Sep 18, 2026 |
| CVE-2026-93653 | MEDIUM | 5.5 | A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to … | Sep 18, 2026 |
| CVE-2026-93652 | HIGH | 7.5 | Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS | Sep 18, 2026 |
| CVE-2026-93576 | HIGH | 7.5 | A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name … | Sep 18, 2026 |
| CVE-2026-93573 | MEDIUM | 6.5 | A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across … | Sep 18, 2026 |
| CVE-2026-93569 | HIGH | 8.2 | A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request … | Sep 18, 2026 |
| CVE-2026-93568 | HIGH | 7.5 | A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object … | Sep 18, 2026 |
| CVE-2026-93567 | HIGH | 7.5 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the … | Sep 18, 2026 |
| CVE-2026-93566 | MEDIUM | 6.5 | A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the … | Sep 18, 2026 |
| CVE-2026-93565 | HIGH | 7.5 | A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A … | Sep 18, 2026 |
| CVE-2026-93564 | HIGH | 7.5 | A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol … | Sep 18, 2026 |
| CVE-2026-93558 | HIGH | 7.5 | A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the … | Sep 18, 2026 |
| CVE-2026-93506 | MEDIUM | 6.3 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a … | Sep 18, 2026 |
| CVE-2026-93505 | LOW | 3.5 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation … | Sep 18, 2026 |
| CVE-2026-85511 | MEDIUM | 4.2 | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution … | Sep 18, 2026 |