Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57327
Total
4582
Critical
17032
High
16910
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18117 | UNKNOWN | — | Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() … | Sep 14, 2026 |
| CVE-2026-13265 | MEDIUM | 6.8 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 14, 2026 |
| CVE-2026-12944 | CRITICAL | 9.6 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components … | Sep 14, 2026 |
| CVE-2026-12759 | MEDIUM | 6.5 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | Sep 14, 2026 |
| CVE-2026-12758 | MEDIUM | 5.4 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | Sep 14, 2026 |
| CVE-2026-12756 | HIGH | 7.1 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could … | Sep 14, 2026 |
| CVE-2026-90896 | UNKNOWN | — | Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before commit 91e273c allows … | Sep 14, 2026 |
| CVE-2026-90824 | LOW | 3.3 | A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to … | Sep 14, 2026 |
| CVE-2026-90820 | MEDIUM | 4.3 | A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to … | Sep 14, 2026 |
| CVE-2026-90819 | HIGH | 7.3 | A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header … | Sep 14, 2026 |
| CVE-2026-90818 | MEDIUM | 4.3 | A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. … | Sep 14, 2026 |
| CVE-2026-86924 | UNKNOWN | — | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … | Sep 14, 2026 |
| CVE-2026-86917 | HIGH | 7.8 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app … | Sep 14, 2026 |
| CVE-2026-86911 | UNKNOWN | — | This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass … | Sep 14, 2026 |
| CVE-2026-86910 | UNKNOWN | — | A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An … | Sep 14, 2026 |
| CVE-2026-86909 | UNKNOWN | — | A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass … | Sep 14, 2026 |
| CVE-2026-86905 | MEDIUM | 5.5 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. … | Sep 14, 2026 |
| CVE-2026-86904 | UNKNOWN | — | A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS … | Sep 14, 2026 |
| CVE-2026-86903 | MEDIUM | 5.5 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, … | Sep 14, 2026 |
| CVE-2026-86902 | UNKNOWN | — | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS … | Sep 14, 2026 |
| CVE-2026-86901 | UNKNOWN | — | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume … | Sep 14, 2026 |
| CVE-2026-86900 | UNKNOWN | — | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume … | Sep 14, 2026 |
| CVE-2026-86898 | UNKNOWN | — | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, … | Sep 14, 2026 |
| CVE-2026-86897 | UNKNOWN | — | This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … | Sep 14, 2026 |
| CVE-2026-86895 | UNKNOWN | — | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS … | Sep 14, 2026 |