VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15756 CVEsRSS

CVE-2026-11727High· 8.1
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS poli…

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS poli…

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.44%via NVD
CVE-2026-91203Medium· 6.0PoC
1w ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating…

▾ TwilightRed Hat · cockpit-filesEPSS 0.10%via NVD
CVE-2026-17619High· 8.6
1w ago

IBM Platform RTM is vulnerable to SQL injection

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

▾ TwilightIBM · spectrum-lsf : IBM Platform RTMEPSS 0.30%via NVD
CVE-2026-17262Medium· 5.4
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

▾ SunlitIBM · iEPSS 0.19%via NVD
CVE-2026-91202Medium· 6.1
1w ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary…

▾ SunlitRed Hat · cockpit-filesEPSS 0.16%via NVD
CVE-2026-80441Critical· 9.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subs…

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.56%via NVD
CVE-2026-75878Critical· 9.1
1w ago

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

▾ MidnightIBM · Sterling File GatewayEPSS 0.64%via NVD
CVE-2026-81656High· 8.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentiall…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.43%via NVD
CVE-2026-81623Medium· 6.3
1w ago

IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.

IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.

▾ SunlitIBM · Guardium Data ProtectionEPSS 0.36%via NVD
CVE-2026-80442Critical· 9.9
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact th…

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.63%via NVD
CVE-2026-82887High· 8.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.78%via NVD
CVE-2026-81657Critical· 9.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.85%via NVD
CVE-2026-82890Medium· 5.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

▾ SunlitIBM · Guardium Data ProtectionEPSS 0.32%via NVD
CVE-2026-81933High· 8.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially re…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.43%via NVD
CVE-2026-81669High· 7.2
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in c…

▾ TwilightIBM · Guardium Data ProtectionEPSS 1.3%via NVD
CVE-2026-82885High· 8.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.50%via NVD
CVE-2026-82832Critical· 9.6
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.61%via NVD
CVE-2026-82340Critical· 9.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may…

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.69%via NVD
CVE-2026-82896High· 7.6
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.49%via NVD
CVE-2026-82893High· 7.8
1w ago

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.14%via NVD
CVE-2026-82892High· 8.1
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.62%via NVD
CVE-2026-84031Critical· 9.0
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.61%via NVD
CVE-2026-82967Critical· 9.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.79%via NVD
CVE-2026-93031High· 8.8
1w ago

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads functi…

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads functi…

▾ TwilightWP Cloud Plugins/_deleeuw_ · Use-your-Drive | Google Drive plugin for WordPressEPSS 0.58%via NVD
CVE-2026-84034High· 8.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in …

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.42%via NVD
CVE-2026-81626High· 8.6
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting i…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.37%via NVD
CVE-2026-77528Medium· 5.3
1w ago

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the com…

▾ Sunlitcrossbario · autobahn-pythonEPSS 0.52%via NVD
CVE-2026-84036High· 7.4
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.34%via NVD
CVE-2026-81937High· 7.2
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potent…

▾ TwilightIBM · Guardium Data ProtectionEPSS 1.5%via NVD
CVE-2026-18869Medium· 6.4
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

▾ SunlitIBM · iEPSS 0.22%via NVD
CVEs tagged “cve.org” — page 114 · VulnSea