CVE Database

132006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13265
6.8 MEDIUM

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 …

Sep 14, 2026
CVE-2026-12944
9.6 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components …

Sep 14, 2026
CVE-2026-12759
6.5 MEDIUM

IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.

Sep 14, 2026
CVE-2026-12758
5.4 MEDIUM

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

Sep 14, 2026
CVE-2026-12756
7.1 HIGH

IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could …

Sep 14, 2026
CVE-2026-90896

Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before commit 91e273c allows …

Sep 14, 2026
CVE-2026-90824
3.3 LOW

A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to …

Sep 14, 2026
CVE-2026-90820
4.3 MEDIUM

A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to …

Sep 14, 2026
CVE-2026-90819
7.3 HIGH

A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header …

Sep 14, 2026
CVE-2026-90818
4.3 MEDIUM

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. …

Sep 14, 2026
CVE-2026-86924
5.5 MEDIUM

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86917
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app …

Sep 14, 2026
CVE-2026-86911
5.5 MEDIUM

This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass …

Sep 14, 2026
CVE-2026-86910
5.5 MEDIUM

A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An …

Sep 14, 2026
CVE-2026-86909
4.4 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass …

Sep 14, 2026
CVE-2026-86905
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. …

Sep 14, 2026
CVE-2026-86904
7.5 HIGH

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS …

Sep 14, 2026
CVE-2026-86903
5.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, …

Sep 14, 2026
CVE-2026-86902
5.5 MEDIUM

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS …

Sep 14, 2026
CVE-2026-86901
7.1 HIGH

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume …

Sep 14, 2026
CVE-2026-86900
6.5 MEDIUM

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume …

Sep 14, 2026
CVE-2026-86898
5.4 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, …

Sep 14, 2026
CVE-2026-86897
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86895
7.5 HIGH

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS …

Sep 14, 2026
CVE-2026-86894
7.5 HIGH

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out …

Sep 14, 2026
CVE-2026-86893
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An …

Sep 14, 2026
CVE-2026-86892
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. …

Sep 14, 2026
CVE-2026-86891
3.5 LOW

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS …

Sep 14, 2026
CVE-2026-86890
4.6 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker …

Sep 14, 2026
CVE-2026-86889
4.8 MEDIUM

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. …

Sep 14, 2026
CVE-2026-86888
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, …

Sep 14, 2026
CVE-2026-86887
3.3 LOW

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS …

Sep 14, 2026
CVE-2026-86886
5.5 MEDIUM

A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86885
6.5 MEDIUM

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An attacker in radio range …

Sep 14, 2026
CVE-2026-86884
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS …

Sep 14, 2026
CVE-2026-86883
5.5 MEDIUM

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may …

Sep 14, 2026
CVE-2026-86882
6.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86881
9.1 CRITICAL

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86879
6.5 MEDIUM

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A remote attacker may be able …

Sep 14, 2026
CVE-2026-86878
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access …

Sep 14, 2026
CVE-2026-86876
5.2 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86870
6.5 MEDIUM

A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86869
6.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing …

Sep 14, 2026
CVE-2026-84636
5.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. …

Sep 14, 2026
CVE-2026-84635
6.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, …

Sep 14, 2026
CVE-2026-84632
7.3 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden …

Sep 14, 2026
CVE-2026-84631
7.8 HIGH

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root …

Sep 14, 2026
CVE-2026-84630
4.7 MEDIUM

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS …

Sep 14, 2026
CVE-2026-84629
7.5 HIGH

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An …

Sep 14, 2026
CVE-2026-84628
5.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, …

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.