Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-39040 | UNKNOWN | — | BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx. | Sep 15, 2026 |
| CVE-2026-39039 | UNKNOWN | — | In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which … | Sep 15, 2026 |
| CVE-2026-39038 | UNKNOWN | — | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx. | Sep 15, 2026 |
| CVE-2026-18115 | UNKNOWN | — | Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user … | Sep 15, 2026 |
| CVE-2026-18113 | UNKNOWN | — | In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so … | Sep 15, 2026 |
| CVE-2026-13210 | HIGH | 7.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 15, 2026 |
| CVE-2026-12910 | MEDIUM | 5.4 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 15, 2026 |
| CVE-2026-12752 | HIGH | 7.1 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could … | Sep 15, 2026 |
| CVE-2026-12751 | MEDIUM | 5.4 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed … | Sep 15, 2026 |
| CVE-2026-12750 | MEDIUM | 6.4 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the … | Sep 15, 2026 |
| CVE-2026-12749 | MEDIUM | 6.4 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the … | Sep 15, 2026 |
| CVE-2026-12742 | MEDIUM | 5.4 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | Sep 15, 2026 |
| CVE-2026-12728 | HIGH | 8.8 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-12667 | HIGH | 7.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-12666 | HIGH | 8.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-12358 | HIGH | 7.5 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | Sep 15, 2026 |
| CVE-2026-12355 | HIGH | 8.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-12354 | HIGH | 7.5 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-12351 | CRITICAL | 9.8 | IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker … | Sep 15, 2026 |
| CVE-2026-12150 | HIGH | 7.0 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-12101 | UNKNOWN | — | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests. | Sep 15, 2026 |
| CVE-2026-11934 | HIGH | 7.2 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | Sep 15, 2026 |
| CVE-2026-11929 | HIGH | 7.5 | IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | Sep 15, 2026 |
| CVE-2026-11928 | UNKNOWN | — | IBM Verify Identity Access is vulnerable to a buffer overflow attack. | Sep 15, 2026 |
| CVE-2026-11927 | UNKNOWN | — | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. | Sep 15, 2026 |