Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7254 | MEDIUM | 5.3 | IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users. | May 27, 2026 |
| CVE-2026-6938 | MEDIUM | 6.5 | IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. | May 27, 2026 |
| CVE-2026-6936 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An … | May 27, 2026 |
| CVE-2026-6053 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range … | May 27, 2026 |
| CVE-2026-6052 | MEDIUM | 6.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. | May 27, 2026 |
| CVE-2026-6051 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small … | May 27, 2026 |
| CVE-2026-5516 | MEDIUM | 4.4 | IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions … | May 27, 2026 |
| CVE-2026-5515 | MEDIUM | 5.5 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. | May 27, 2026 |
| CVE-2026-5065 | HIGH | 8.8 | IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, … | May 27, 2026 |
| CVE-2026-4410 | MEDIUM | 4.8 | IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to … | May 27, 2026 |
| CVE-2026-48972 | HIGH | 7.5 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion. … | May 27, 2026 |
| CVE-2026-48971 | MEDIUM | 4.3 | Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for … | May 27, 2026 |
| CVE-2026-47104 | MEDIUM | 4.0 | libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying … | May 27, 2026 |
| CVE-2026-46103 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix devres lifetime USB drivers bind to USB interfaces and any device managed … | May 27, 2026 |
| CVE-2026-46102 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abort_strp() When the stream parser is aborted, for example … | May 27, 2026 |
| CVE-2026-46101 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: reject zero shift in nft_bitwise Reject zero shift operands for nft_bitwise left and right … | May 27, 2026 |
| CVE-2026-46100 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs: afs: revert mmap_prepare() change Partially reverts commit 9d5403b1036c ("fs: convert most other generic_file_*mmap() users … | May 27, 2026 |
| CVE-2026-46099 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call … | May 27, 2026 |
| CVE-2026-46098 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: caif: clear client service pointer on teardown `caif_connect()` can tear down an existing client … | May 27, 2026 |
| CVE-2026-46097 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Input: edt-ft5x06 - fix use-after-free in debugfs teardown The commit 68743c500c6e ("Input: edt-ft5x06 - use … | May 27, 2026 |
| CVE-2026-46096 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() tpm2_read_public() calls tpm_buf_init() but fails to call tpm_buf_destroy() on … | May 27, 2026 |
| CVE-2026-46095 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: raise barrier before state machine transition Move the barrier raise operation before calling llbitmap_state_machine() … | May 27, 2026 |
| CVE-2026-46094 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access The bounds check for the … | May 27, 2026 |
| CVE-2026-46093 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when … | May 27, 2026 |
| CVE-2026-46092 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: check for PCI upstream bridge existence pci_upstream_bridge() returns NULL if the device is … | May 27, 2026 |