Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57327
Total
4582
Critical
17032
High
16910
Medium
CVE ID Severity Score Description Published
CVE-2026-18117 UNKNOWN — Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() … Sep 14, 2026
CVE-2026-13265 MEDIUM 6.8 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 14, 2026
CVE-2026-12944 CRITICAL 9.6 IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components … Sep 14, 2026
CVE-2026-12759 MEDIUM 6.5 IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. Sep 14, 2026
CVE-2026-12758 MEDIUM 5.4 IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. Sep 14, 2026
CVE-2026-12756 HIGH 7.1 IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could … Sep 14, 2026
CVE-2026-90896 UNKNOWN — Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before commit 91e273c allows … Sep 14, 2026
CVE-2026-90824 LOW 3.3 A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to … Sep 14, 2026
CVE-2026-90820 MEDIUM 4.3 A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to … Sep 14, 2026
CVE-2026-90819 HIGH 7.3 A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header … Sep 14, 2026
CVE-2026-90818 MEDIUM 4.3 A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. … Sep 14, 2026
CVE-2026-86924 UNKNOWN — A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … Sep 14, 2026
CVE-2026-86917 HIGH 7.8 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app … Sep 14, 2026
CVE-2026-86911 UNKNOWN — This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass … Sep 14, 2026
CVE-2026-86910 UNKNOWN — A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An … Sep 14, 2026
CVE-2026-86909 UNKNOWN — A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass … Sep 14, 2026
CVE-2026-86905 MEDIUM 5.5 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. … Sep 14, 2026
CVE-2026-86904 UNKNOWN — A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS … Sep 14, 2026
CVE-2026-86903 MEDIUM 5.5 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, … Sep 14, 2026
CVE-2026-86902 UNKNOWN — A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS … Sep 14, 2026
CVE-2026-86901 UNKNOWN — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume … Sep 14, 2026
CVE-2026-86900 UNKNOWN — An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume … Sep 14, 2026
CVE-2026-86898 UNKNOWN — A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, … Sep 14, 2026
CVE-2026-86897 UNKNOWN — This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … Sep 14, 2026
CVE-2026-86895 UNKNOWN — An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS … Sep 14, 2026