Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11926 | HIGH | 7.5 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | Sep 15, 2026 |
| CVE-2026-11921 | UNKNOWN | — | IBM Verify Identity Access containers may not apply management password change operations correctly. | Sep 15, 2026 |
| CVE-2026-11918 | MEDIUM | 5.4 | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload … | Sep 15, 2026 |
| CVE-2026-11864 | MEDIUM | 6.5 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and … | Sep 15, 2026 |
| CVE-2026-11729 | HIGH | 8.5 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2026-11728 | HIGH | 8.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 15, 2026 |
| CVE-2025-66974 | HIGH | 7.5 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) … | Sep 15, 2026 |
| CVE-2026-91855 | MEDIUM | 5.3 | A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the … | Sep 15, 2026 |
| CVE-2026-91854 | MEDIUM | 4.3 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc … | Sep 15, 2026 |
| CVE-2026-91853 | HIGH | 7.4 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn … | Sep 15, 2026 |
| CVE-2026-89026 | CRITICAL | 9.8 | The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file … | Sep 15, 2026 |
| CVE-2026-89022 | HIGH | 7.4 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating … | Sep 15, 2026 |
| CVE-2026-81897 | UNKNOWN | — | In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an … | Sep 15, 2026 |
| CVE-2026-81896 | UNKNOWN | — | Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard … | Sep 15, 2026 |
| CVE-2026-81895 | UNKNOWN | — | In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block … | Sep 15, 2026 |
| CVE-2026-81894 | UNKNOWN | — | Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup … | Sep 15, 2026 |
| CVE-2026-79705 | MEDIUM | 4.5 | A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks … | Sep 15, 2026 |
| CVE-2026-79699 | MEDIUM | 4.4 | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory … | Sep 15, 2026 |
| CVE-2026-63443 | HIGH | 8.3 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts … | Sep 15, 2026 |
| CVE-2026-59160 | HIGH | 8.8 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts … | Sep 15, 2026 |
| CVE-2026-58201 | UNKNOWN | — | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses … | Sep 15, 2026 |
| CVE-2026-58200 | HIGH | 7.1 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose … | Sep 15, 2026 |
| CVE-2026-55863 | MEDIUM | 5.3 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, … | Sep 15, 2026 |
| CVE-2026-55692 | HIGH | 7.5 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video … | Sep 15, 2026 |
| CVE-2026-55691 | HIGH | 8.6 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video … | Sep 15, 2026 |