Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57401
Total
4583
Critical
17032
High
16919
Medium
CVE ID Severity Score Description Published
CVE-2026-14276 MEDIUM 6.3 IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges … Sep 14, 2026
CVE-2026-14275 MEDIUM 6.3 IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges … Sep 14, 2026
CVE-2026-13293 HIGH 8.8 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 14, 2026
CVE-2026-13287 HIGH 7.1 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 14, 2026
CVE-2026-13285 HIGH 7.1 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 14, 2026
CVE-2026-13277 UNKNOWN — IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a … Sep 14, 2026
CVE-2026-13276 MEDIUM 6.1 IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity … Sep 14, 2026
CVE-2026-13275 HIGH 7.1 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 … Sep 14, 2026
CVE-2026-13272 UNKNOWN — IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks … Sep 14, 2026
CVE-2026-13260 UNKNOWN — IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. Sep 14, 2026
CVE-2026-13107 HIGH 7.1 IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. Sep 14, 2026
CVE-2026-12767 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the … Sep 14, 2026
CVE-2026-12766 MEDIUM 5.4 IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the … Sep 14, 2026
CVE-2026-12765 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the … Sep 14, 2026
CVE-2026-12763 MEDIUM 4.2 IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in … Sep 14, 2026
CVE-2026-90816 MEDIUM 4.3 A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of … Sep 14, 2026
CVE-2026-90815 MEDIUM 6.3 A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component … Sep 14, 2026
CVE-2026-90814 MEDIUM 6.3 A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the … Sep 14, 2026
CVE-2026-90813 MEDIUM 4.3 A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. … Sep 14, 2026
CVE-2026-82028 HIGH 8.8 Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by … Sep 14, 2026
CVE-2026-73497 MEDIUM 6.5 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and … Sep 14, 2026
CVE-2026-73496 HIGH 7.7 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a … Sep 14, 2026
CVE-2026-65838 HIGH 8.2 Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length … Sep 14, 2026
CVE-2026-55244 MEDIUM 5.0 ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by … Sep 14, 2026
CVE-2026-55209 CRITICAL 9.8 resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword … Sep 14, 2026