CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81210
7.7 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the …

Sep 10, 2026
CVE-2026-81207
8.5 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an …

Sep 10, 2026
CVE-2026-80436
8.5 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues …

Sep 10, 2026
CVE-2026-80434
7.4 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due …

Sep 10, 2026
CVE-2026-80380
7.1 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

Sep 10, 2026
CVE-2026-80378
8.5 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

Sep 10, 2026
CVE-2026-79742
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

Sep 10, 2026
CVE-2026-78575
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the …

Sep 10, 2026
CVE-2026-78571
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.

Sep 10, 2026
CVE-2026-78569
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

Sep 10, 2026
CVE-2026-76059
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated …

Sep 10, 2026
CVE-2026-75777
8.8 HIGH

IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the …

Sep 10, 2026
CVE-2026-75624
8.8 HIGH

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.

Sep 10, 2026
CVE-2026-71647
7.5 HIGH

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in …

Sep 10, 2026
CVE-2026-71645
7.5 HIGH

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration …

Sep 10, 2026
CVE-2026-71643
7.5 HIGH

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component

Sep 10, 2026
CVE-2026-45770
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a …

Sep 10, 2026
CVE-2026-45769
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow …

Sep 10, 2026
CVE-2026-45768
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP …

Sep 10, 2026
CVE-2026-45766
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state …

Sep 10, 2026
CVE-2026-45765
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer …

Sep 10, 2026
CVE-2026-45762
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker …

Sep 10, 2026
CVE-2026-2310
7.8 HIGH

IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker …

Sep 10, 2026
CVE-2025-57231
7.5 HIGH

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

Sep 10, 2026
CVE-2026-79592
7.5 HIGH

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

Sep 10, 2026
CVE-2026-79591
7.8 HIGH

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

Sep 10, 2026
CVE-2026-63427
7.8 HIGH

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

Sep 10, 2026
CVE-2026-45759
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform …

Sep 10, 2026
CVE-2026-19136
7.8 HIGH

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system …

Sep 10, 2026
CVE-2026-18994
7.1 HIGH

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local …

Sep 10, 2026
CVE-2026-11813
7.8 HIGH

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

Sep 10, 2026
CVE-2026-89087
7.3 HIGH

The cstruct package before 6.3.0 for OCaml mishandles indexes.

Sep 10, 2026
CVE-2026-89054
8.2 HIGH

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for …

Sep 10, 2026
CVE-2026-89011
7.1 HIGH

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted …

Sep 10, 2026
CVE-2026-88036
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88034
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88033
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88021
7.1 HIGH

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it …

Sep 10, 2026
CVE-2026-87993
7.7 HIGH

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template …

Sep 10, 2026
CVE-2026-87090
8.3 HIGH

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's …

Sep 10, 2026
CVE-2026-89046
8.2 HIGH

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values …

Sep 10, 2026
CVE-2026-89043
7.4 HIGH

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any …

Sep 10, 2026
CVE-2026-88053
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of …

Sep 10, 2026
CVE-2026-88052
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and …

Sep 10, 2026
CVE-2026-88051
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved …

Sep 10, 2026
CVE-2026-88031
8.1 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88030
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88029
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88027
7.1 HIGH

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded …

Sep 10, 2026
CVE-2026-88025
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.