VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29980 CVEsRSS

CVE-2026-16673High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.42%via NVD
CVE-2026-90815Medium· 6.3PoC
2w ago

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-o…

▾ TwilightRed Hat · FFmpegEPSS 0.42%via NVD
CVE-2026-19624High· 7.8
2w ago

A flaw was found in NetworkManager-l2tp

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can…

▾ TwilightFedora · NetworkManager-l2tpEPSS 0.13%via NVD
CVE-2026-16428High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.54%via NVD
CVE-2026-73496High· 7.7PoC
2w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

▾ Midnightsooperset · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-16435Medium· 5.9
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.31%via NVD
CVE-2026-16432High· 7.7
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.34%via NVD
CVE-2026-73497Medium· 6.5
2w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url hea…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.38%via NVD
CVE-2026-16338Critical· 9.9
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

▾ MidnightIBM · DataStage on Cloud Pak for DataEPSS 0.43%via NVD
CVE-2026-16190Low· 3.1
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.16%via NVD
CVE-2026-16189Medium· 4.8
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.22%via NVD
CVE-2026-16188Medium· 5.3
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.27%via NVD
CVE-2026-16187Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-82028High· 8.8
2w ago

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that…

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that…

▾ Twilightabsmach · magistralaEPSS 0.60%via NVD
CVE-2026-16185Medium· 6.4
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.20%via NVD
CVE-2026-16186Medium· 5.4
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-15887Medium· 5.4
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-15955High· 7.5
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

▾ TwilightIBM · Db2EPSS 0.40%via NVD
CVE-2026-90816Medium· 4.3PoC
2w ago

A vulnerability was found in FFmpeg 8.0.x

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial…

▾ TwilightRed Hat · FFmpegEPSS 0.58%via NVD
CVE-2026-65838High· 8.2
2w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

▾ Twilightzalando · skipperEPSS 0.46%via NVD
CVE-2026-15634Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-19816High· 7.1
2w ago

A flaw was found in PackageKit

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transac…

▾ TwilightFedora · PackageKitEPSS 0.10%via NVD
CVE-2026-16147Medium· 6.8
2w ago

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which does not…

▾ Sunlitzephyrproject · zephyrEPSS 0.18%via NVD
CVE-2026-15924Medium· 5.9
2w ago

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_sessio…

▾ Sunlitzephyrproject · zephyrEPSS 0.31%via NVD
CVE-2026-16148Medium· 4.6
2w ago

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2…

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2…

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-18119Critical· 9.0⚖ disputed
2w ago

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administra…

▾ Midnightconcretecms · concrete_cmsEPSS 0.31%via NVD
CVE-2026-18251Medium· 4.3
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

▾ SunlitIBM · iEPSS 0.14%via NVD
CVE-2026-16466High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.91%via NVD
CVE-2026-16335High· 8.1
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.42%via NVD
CVE-2026-15396Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVEs tagged “nvd” — page 325 · VulnSea