VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15796 CVEsRSS

CVE-2026-11381High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.33%via NVD
CVE-2026-11378High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

▾ Twilightibm · mqEPSS 0.34%via NVD
CVE-2026-11375High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.

▾ Twilightibm · mqEPSS 0.35%via NVD
CVE-2026-10858Critical· 9.9
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

▾ MidnightIBM · MQ for HPE NonStopEPSS 0.37%via NVD
CVE-2026-10853High· 7.5
1w ago

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

▾ Twilightibm · mqEPSS 0.37%via NVD
CVE-2026-10841Medium· 4.2
1w ago

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

▾ SunlitIBM · CICS TX AdvancedEPSS 0.16%via NVD
CVE-2026-10751High· 7.5
1w ago

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

▾ TwilightIBM · MQEPSS 0.37%via NVD
CVE-2026-10747Critical· 10.0
1w ago

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

▾ MidnightIBM · MQ ApplianceEPSS 0.57%via NVD
CVE-2026-10744High· 7.5
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.27%via NVD
CVE-2026-10575High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.

▾ Twilightibm · mqEPSS 0.28%via NVD
CVE-2026-10030High· 7.1
1w ago

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

▾ TwilightIBM · MQEPSS 0.23%via NVD
CVE-2026-10027High· 8.1
1w ago

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

▾ Twilightibm · mqEPSS 0.38%via NVD
CVE-2025-61682High· 8.6PoC
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…

▾ Midnightmediawiki · mediawiki/semantic-media-wikiEPSS 0.29%via NVD
CVE-2025-36421Medium· 5.9
1w ago

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

▾ SunlitIBM · ControllerEPSS 0.16%via NVD
CVE-2025-36178Medium· 5.4
1w ago

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

▾ SunlitIBM · ControllerEPSS 0.25%via NVD
CVE-2025-36147Medium· 6.1
1w ago

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web U…

▾ SunlitIBM · Financial Transaction Manager for SWIFT Services for MultiplatformsEPSS 0.20%via NVD
CVE-2025-36076Medium· 4.3
1w ago

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.

▾ SunlitIBM · Cognos AnalyticsEPSS 0.21%via NVD
CVE-2025-36045Medium· 4.3
1w ago

IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

▾ SunlitIBM · TS4300EPSS 0.26%via NVD
CVE-2025-33147Medium· 5.9
1w ago

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.

▾ SunlitIBM · Cognos AnalyticsEPSS 0.17%via NVD
CVE-2025-33141Medium· 6.5
1w ago

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.

▾ SunlitIBM · QRadarEPSS 0.27%via NVD
CVE-2025-15399Critical· 10.0
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

▾ MidnightIBM · Common LicensingEPSS 0.18%via NVD
CVE-2026-7006High· 7.3PoC
1w ago

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

▾ MidnightSublime HQ Pty Ltd · Sublime Text 4EPSS 0.13%via NVD
CVE-2026-93689Medium· 5.5
1w ago

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of se…

▾ Sunlitwinfsp · winfspEPSS 0.15%via NVD
CVE-2026-93688High· 7.5
1w ago

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's …

▾ Twilightsgl-project · sglangEPSS 0.72%via NVD
CVE-2026-93687High· 7.5PoC
1w ago

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Nod…

▾ Midnightmicromatch · bracesEPSS 0.74%via NVD
CVE-2026-93690High· 7.5PoC
1w ago

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDot…

▾ Midnightgarycourt · uri-jsEPSS 0.68%via NVD
CVE-2026-81945Medium· 6.6
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer …

▾ SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.58%via NVD
CVE-2026-81942High· 8.8
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without suffic…

▾ TwilightPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 1.9%via NVD
CVE-2026-93531Medium· 4.3PoC
1w ago

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated re…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.23%via NVD
CVE-2026-81946Medium· 4.4
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device confi…

▾ SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.17%via NVD
CVEs tagged “cve.org” — page 121 · VulnSea