Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57083
Total
4536
Critical
16949
High
16800
Medium
CVE ID Severity Score Description Published
CVE-2026-39040 UNKNOWN — BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx. Sep 15, 2026
CVE-2026-39039 UNKNOWN — In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which … Sep 15, 2026
CVE-2026-39038 UNKNOWN — BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx. Sep 15, 2026
CVE-2026-18115 UNKNOWN — Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user … Sep 15, 2026
CVE-2026-18113 UNKNOWN — In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so … Sep 15, 2026
CVE-2026-13210 HIGH 7.7 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 15, 2026
CVE-2026-12910 MEDIUM 5.4 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 15, 2026
CVE-2026-12752 HIGH 7.1 IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could … Sep 15, 2026
CVE-2026-12751 MEDIUM 5.4 IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed … Sep 15, 2026
CVE-2026-12750 MEDIUM 6.4 IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the … Sep 15, 2026
CVE-2026-12749 MEDIUM 6.4 IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the … Sep 15, 2026
CVE-2026-12742 MEDIUM 5.4 IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. Sep 15, 2026
CVE-2026-12728 HIGH 8.8 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 15, 2026
CVE-2026-12667 HIGH 7.1 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 15, 2026
CVE-2026-12666 HIGH 8.1 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 15, 2026
CVE-2026-12358 HIGH 7.5 IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. Sep 15, 2026
CVE-2026-12355 HIGH 8.1 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 15, 2026
CVE-2026-12354 HIGH 7.5 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 15, 2026
CVE-2026-12351 CRITICAL 9.8 IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker … Sep 15, 2026
CVE-2026-12150 HIGH 7.0 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 15, 2026
CVE-2026-12101 UNKNOWN — IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests. Sep 15, 2026
CVE-2026-11934 HIGH 7.2 IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. Sep 15, 2026
CVE-2026-11929 HIGH 7.5 IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. Sep 15, 2026
CVE-2026-11928 UNKNOWN — IBM Verify Identity Access is vulnerable to a buffer overflow attack. Sep 15, 2026
CVE-2026-11927 UNKNOWN — IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. Sep 15, 2026