VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18479 CVEsRSS

CVE-2026-13275High· 7.1
2w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an auth…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an auth…

▾ TwilightIBM · MQEPSS 0.25%via NVD
CVE-2026-90814Medium· 6.3PoC
2w ago

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument pat…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.37%via NVD
CVE-2026-90813Medium· 4.3PoC
2w ago

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in inc…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.55%via NVD
CVE-2026-18065Medium· 5.3
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

▾ SunlitIBM · iEPSS 0.31%via NVD
CVE-2026-17628Medium· 5.4
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

▾ SunlitIBM · Langflow OSSEPSS 0.34%via NVD
CVE-2026-17467High· 8.2
2w ago

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.

▾ TwilightIBM · Cloud Pak for Data System (Yosemite 1.0)EPSS 0.21%via NVD
CVE-2026-17416High· 7.8
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.14%via NVD
CVE-2026-17463Medium· 6.5
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.

▾ SunlitIBM · Db2EPSS 0.34%via NVD
CVE-2026-17133High· 7.8
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.15%via NVD
CVE-2026-17047Medium· 5.4
2w ago

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

▾ SunlitIBM · Db2 Mirror for iEPSS 0.12%via NVD
CVE-2026-16702Medium· 6.5
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.

▾ SunlitIBM · Db2EPSS 0.34%via NVD
CVE-2026-16673High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.42%via NVD
CVE-2026-90815Medium· 6.3PoC
2w ago

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-o…

▾ TwilightRed Hat · FFmpegEPSS 0.42%via NVD
CVE-2026-19624High· 7.8
2w ago

A flaw was found in NetworkManager-l2tp

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can…

▾ TwilightFedora · NetworkManager-l2tpEPSS 0.13%via NVD
CVE-2026-16428High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.54%via NVD
CVE-2026-73496High· 7.7PoC
2w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

▾ Midnightsooperset · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-16435Medium· 5.9
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.31%via NVD
CVE-2026-16432High· 7.7
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.34%via NVD
CVE-2026-73497Medium· 6.5
2w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url hea…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.38%via NVD
CVE-2026-16338Critical· 9.9
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

▾ MidnightIBM · DataStage on Cloud Pak for DataEPSS 0.43%via NVD
CVE-2026-16190Low· 3.1
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.16%via NVD
CVE-2026-16189Medium· 4.8
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.22%via NVD
CVE-2026-16188Medium· 5.3
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.27%via NVD
CVE-2026-16187Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-82028High· 8.8
2w ago

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that…

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that…

▾ Twilightabsmach · magistralaEPSS 0.60%via NVD
CVE-2026-16185Medium· 6.4
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.20%via NVD
CVE-2026-16186Medium· 5.4
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-15887Medium· 5.4
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-15955High· 7.5
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

▾ TwilightIBM · Db2EPSS 0.40%via NVD
CVE-2026-90816Medium· 4.3PoC
2w ago

A vulnerability was found in FFmpeg 8.0.x

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial…

▾ TwilightRed Hat · FFmpegEPSS 0.58%via NVD
CVEs tagged “cve.org” — page 323 · VulnSea