Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57327
Total
4582
Critical
17032
High
16910
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14277 | MEDIUM | 6.3 | IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to … | Sep 14, 2026 |
| CVE-2026-14276 | MEDIUM | 6.3 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges … | Sep 14, 2026 |
| CVE-2026-14275 | MEDIUM | 6.3 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges … | Sep 14, 2026 |
| CVE-2026-13293 | HIGH | 8.8 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 14, 2026 |
| CVE-2026-13287 | HIGH | 7.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 14, 2026 |
| CVE-2026-13285 | HIGH | 7.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 14, 2026 |
| CVE-2026-13277 | UNKNOWN | — | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a … | Sep 14, 2026 |
| CVE-2026-13276 | MEDIUM | 6.1 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity … | Sep 14, 2026 |
| CVE-2026-13275 | HIGH | 7.1 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … | Sep 14, 2026 |
| CVE-2026-13272 | UNKNOWN | — | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks … | Sep 14, 2026 |
| CVE-2026-13260 | UNKNOWN | — | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | Sep 14, 2026 |
| CVE-2026-13107 | HIGH | 7.1 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. | Sep 14, 2026 |
| CVE-2026-12767 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the … | Sep 14, 2026 |
| CVE-2026-12766 | MEDIUM | 5.4 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the … | Sep 14, 2026 |
| CVE-2026-12765 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the … | Sep 14, 2026 |
| CVE-2026-12763 | MEDIUM | 4.2 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in … | Sep 14, 2026 |
| CVE-2026-90816 | MEDIUM | 4.3 | A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of … | Sep 14, 2026 |
| CVE-2026-90815 | MEDIUM | 6.3 | A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component … | Sep 14, 2026 |
| CVE-2026-90814 | MEDIUM | 6.3 | A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the … | Sep 14, 2026 |
| CVE-2026-90813 | MEDIUM | 4.3 | A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. … | Sep 14, 2026 |
| CVE-2026-82028 | HIGH | 8.8 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by … | Sep 14, 2026 |
| CVE-2026-73497 | MEDIUM | 6.5 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and … | Sep 14, 2026 |
| CVE-2026-73496 | HIGH | 7.7 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a … | Sep 14, 2026 |
| CVE-2026-65838 | HIGH | 8.2 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length … | Sep 14, 2026 |
| CVE-2026-55244 | MEDIUM | 5.0 | ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by … | Sep 14, 2026 |