Export limit exceeded: 393033 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (393033 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12766 | 1 Ibm | 1 Langflow Oss | 2026-09-15 | 5.4 Medium |
| IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | ||||
| CVE-2026-12763 | 1 Ibm | 1 Langflow Oss | 2026-09-15 | 4.2 Medium |
| IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component. | ||||
| CVE-2026-12759 | 1 Ibm | 1 Cloud Pak For Business Automation | 2026-09-15 | 6.5 Medium |
| IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | ||||
| CVE-2026-12758 | 1 Ibm | 1 Cloud Pak For Business Automation | 2026-09-15 | 5.4 Medium |
| IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | ||||
| CVE-2026-12742 | 1 Ibm | 1 Business Automation Workflow Containers And Traditional | 2026-09-15 | 5.4 Medium |
| IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | ||||
| CVE-2026-12358 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-09-15 | 7.5 High |
| IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | ||||
| CVE-2026-12355 | 1 Ibm | 1 Mq | 2026-09-15 | 8.1 High |
| IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution. | ||||
| CVE-2026-11926 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-09-15 | 7.5 High |
| IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | ||||
| CVE-2025-70820 | 2026-09-15 | 3.5 Low | ||
| Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | ||||
| CVE-2024-14029 | 1 Tornadoweb | 1 Tornado | 2026-09-15 | 7.5 High |
| Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization. | ||||
| CVE-2023-54398 | 2026-09-15 | 9.8 Critical | ||
| Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13. | ||||
| CVE-2026-84653 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 3.5 Low |
| Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. | ||||
| CVE-2026-55770 | 1 Openbao | 1 Openbao | 2026-09-15 | 6.8 Medium |
| OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5. | ||||
| CVE-2026-84655 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.3 Medium |
| Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses. | ||||
| CVE-2026-84656 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.3 Medium |
| A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to. | ||||
| CVE-2026-84555 | 1 Apple | 1 Macos | 2026-09-15 | 5.5 Medium |
| An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data. | ||||
| CVE-2026-84657 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.2 Medium |
| In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | ||||
| CVE-2026-18065 | 1 Ibm | 1 I | 2026-09-15 | 5.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i. | ||||
| CVE-2026-16435 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 5.9 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features. | ||||
| CVE-2026-16189 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 4.8 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | ||||