Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56334
Total
4455
Critical
16700
High
16518
Medium
CVE ID Severity Score Description Published
CVE-2026-10747 CRITICAL 10.0 IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow … Sep 18, 2026
CVE-2026-10744 HIGH 7.5 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to … Sep 18, 2026
CVE-2026-10575 HIGH 8.8 IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing … Sep 18, 2026
CVE-2026-10030 HIGH 7.1 IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks. Sep 18, 2026
CVE-2026-10027 HIGH 8.1 IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed … Sep 18, 2026
CVE-2025-61682 HIGH 8.6 Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and … Sep 18, 2026
CVE-2025-53837 CRITICAL 9.9 XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior … Sep 18, 2026
CVE-2025-36421 MEDIUM 5.9 IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information … Sep 18, 2026
CVE-2025-36178 MEDIUM 5.4 IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of … Sep 18, 2026
CVE-2025-36147 MEDIUM 6.1 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed … Sep 18, 2026
CVE-2025-36076 MEDIUM 4.3 IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user … Sep 18, 2026
CVE-2025-36045 MEDIUM 4.3 IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of … Sep 18, 2026
CVE-2025-33147 MEDIUM 5.9 IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused … Sep 18, 2026
CVE-2025-33141 MEDIUM 6.5 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions … Sep 18, 2026
CVE-2025-15399 CRITICAL 10.0 IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow … Sep 18, 2026
CVE-2025-14754 HIGH 8.8 IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation … Sep 18, 2026
CVE-2025-14753 HIGH 7.5 IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL … Sep 18, 2026
CVE-2026-93685 MEDIUM 5.4 A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework … Sep 18, 2026
CVE-2026-93676 LOW 3.2 xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the … Sep 18, 2026
CVE-2026-93660 MEDIUM 6.5 SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can … Sep 18, 2026
CVE-2026-93659 HIGH 8.7 Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in … Sep 18, 2026
CVE-2026-93658 HIGH 7.0 uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned … Sep 18, 2026
CVE-2026-93657 HIGH 7.5 hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful … Sep 18, 2026
CVE-2026-93653 MEDIUM 5.5 A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to … Sep 18, 2026
CVE-2026-93652 HIGH 7.5 Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS Sep 18, 2026