VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18336 CVEsRSS

CVE-2026-12354High· 7.5
2w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

▾ TwilightIBM · MQEPSS 0.33%via NVD
CVE-2026-12150High· 7.0
2w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trus…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trus…

▾ TwilightIBM · MQEPSS 0.17%via NVD
CVE-2026-12101High· 8.1
2w ago

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.

▾ TwilightIBM · Verify Identity AccessEPSS 0.27%via NVD
CVE-2026-11934High· 7.2
2w ago

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

▾ TwilightIBM · Verify Identity AccessEPSS 0.32%via NVD
CVE-2026-11928Critical· 9.8
2w ago

IBM Verify Identity Access is vulnerable to a buffer overflow attack.

IBM Verify Identity Access is vulnerable to a buffer overflow attack.

▾ MidnightIBM · Verify Identity AccessEPSS 0.29%via NVD
CVE-2026-11929High· 7.5
2w ago

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

▾ TwilightIBM · Verify Identity AccessEPSS 0.16%via NVD
CVE-2026-11926High· 7.5
2w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.31%via NVD
CVE-2026-53459Critical· 9.3
2w ago

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flood…

▾ Midnightmaziggy · bambuddyEPSS 0.76%via NVD
CVE-2026-11927Medium· 6.5
2w ago

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

▾ SunlitIBM · Verify Identity AccessEPSS 0.17%via NVD
CVE-2026-39038Medium· 6.1PoC
2w ago

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-11921Critical· 9.1
2w ago

IBM Verify Identity Access containers may not apply management password change operations correctly.

IBM Verify Identity Access containers may not apply management password change operations correctly.

▾ MidnightIBM · Verify Identity AccessEPSS 0.23%via NVD
CVE-2026-11918Medium· 5.4
2w ago

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

▾ SunlitIBM · ContextForge MCP GatewayEPSS 0.16%via NVD
CVE-2026-81898High· 7.5
2w ago

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the sess…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.44%via NVD
CVE-2026-39039Medium· 5.3
2w ago

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

▾ SunlitEPSS 0.37%via NVD
CVE-2026-11864Medium· 6.5
2w ago

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vuln…

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vuln…

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.22%via NVD
CVE-2026-39040Medium· 5.4
2w ago

BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.

BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-11729High· 8.5
2w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

▾ TwilightIBM · MQEPSS 0.31%via NVD
CVE-2026-12358High· 7.5
2w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.39%via NVD
CVE-2026-18113High· 7.5
2w ago

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-12742Medium· 5.4
2w ago

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

▾ SunlitIBM · Business Automation Workflow containers and traditionalEPSS 0.17%via NVD
CVE-2026-91855Medium· 5.3PoC
2w ago

A security flaw has been discovered in Open5GS up to 2.7.7

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation results in denial of s…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-89026Critical· 9.8PoC
2w ago

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

▾ AbyssalIssabel Foundation · Issabel FrameworkEPSS 0.69%via NVD
CVE-2026-81897Medium· 5.4⚖ disputed
2w ago

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote a…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.17%via NVD
CVE-2026-81896Medium· 5.4⚖ disputed
2w ago

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81895High· 7.2
2w ago

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

▾ Twilightconcretecms · concrete_cmsEPSS 0.51%via NVD
CVE-2026-81894Medium· 5.4⚖ disputed
2w ago

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-63443High· 8.3
2w ago

Coder allows organizations to provision remote development environments via Terraform

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…

▾ Twilightcoder · coderEPSS 0.76%via NVD
CVE-2026-58201High· 8.7
2w ago

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled …

▾ Twilightmerill · lokkaEPSS 0.48%via NVD
CVE-2026-21588High· 7.1
2w ago

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

▾ TwilightAtlassian · Confluence Data CenterEPSS 0.29%via NVD
CVE-2026-21587High· 7.1
2w ago

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to…

▾ TwilightAtlassian · Jira Service Management Data CenterEPSS 0.32%via NVD
CVEs tagged “cve.org” — page 295 · VulnSea