Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41921
Total
3420
Critical
12394
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-75165 UNKNOWN An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic … Sep 04, 2026
CVE-2026-75164 MEDIUM 6.5 An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve … Sep 04, 2026
CVE-2026-75163 MEDIUM 6.5 An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any … Sep 04, 2026
CVE-2026-75162 UNKNOWN An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the … Sep 04, 2026
CVE-2026-75161 UNKNOWN An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to … Sep 04, 2026
CVE-2026-75160 CRITICAL 9.1 An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. Sep 04, 2026
CVE-2026-5522 MEDIUM 6.7 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own … Sep 04, 2026
CVE-2026-44402 CRITICAL 9.8 Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute … Sep 04, 2026
CVE-2026-19649 MEDIUM 6.2 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker … Sep 04, 2026
CVE-2026-19645 MEDIUM 6.5 IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause … Sep 04, 2026
CVE-2026-19306 HIGH 7.7 IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT … Sep 04, 2026
CVE-2026-19305 HIGH 8.6 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. Sep 04, 2026
CVE-2026-19304 HIGH 7.7 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. Sep 04, 2026
CVE-2026-19303 HIGH 8.1 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a … Sep 04, 2026
CVE-2026-19302 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. Sep 04, 2026
CVE-2026-19301 MEDIUM 5.0 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. Sep 04, 2026
CVE-2026-19300 HIGH 7.5 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. Sep 04, 2026
CVE-2026-19299 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. Sep 04, 2026
CVE-2026-19298 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build … Sep 04, 2026
CVE-2026-19283 HIGH 7.7 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by … Sep 04, 2026
CVE-2026-19274 CRITICAL 9.6 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another … Sep 04, 2026
CVE-2026-18905 HIGH 7.7 IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding … Sep 04, 2026
CVE-2026-18887 MEDIUM 6.5 IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to … Sep 04, 2026
CVE-2026-18858 LOW 3.3 IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. Sep 04, 2026
CVE-2026-18658 CRITICAL 9.8 IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements … Sep 04, 2026