Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41921
Total
3420
Critical
12394
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75165 | UNKNOWN | — | An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic … | Sep 04, 2026 |
| CVE-2026-75164 | MEDIUM | 6.5 | An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve … | Sep 04, 2026 |
| CVE-2026-75163 | MEDIUM | 6.5 | An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any … | Sep 04, 2026 |
| CVE-2026-75162 | UNKNOWN | — | An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the … | Sep 04, 2026 |
| CVE-2026-75161 | UNKNOWN | — | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to … | Sep 04, 2026 |
| CVE-2026-75160 | CRITICAL | 9.1 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | Sep 04, 2026 |
| CVE-2026-5522 | MEDIUM | 6.7 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own … | Sep 04, 2026 |
| CVE-2026-44402 | CRITICAL | 9.8 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute … | Sep 04, 2026 |
| CVE-2026-19649 | MEDIUM | 6.2 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker … | Sep 04, 2026 |
| CVE-2026-19645 | MEDIUM | 6.5 | IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause … | Sep 04, 2026 |
| CVE-2026-19306 | HIGH | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT … | Sep 04, 2026 |
| CVE-2026-19305 | HIGH | 8.6 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. | Sep 04, 2026 |
| CVE-2026-19304 | HIGH | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. | Sep 04, 2026 |
| CVE-2026-19303 | HIGH | 8.1 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a … | Sep 04, 2026 |
| CVE-2026-19302 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | Sep 04, 2026 |
| CVE-2026-19301 | MEDIUM | 5.0 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. | Sep 04, 2026 |
| CVE-2026-19300 | HIGH | 7.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. | Sep 04, 2026 |
| CVE-2026-19299 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. | Sep 04, 2026 |
| CVE-2026-19298 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build … | Sep 04, 2026 |
| CVE-2026-19283 | HIGH | 7.7 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by … | Sep 04, 2026 |
| CVE-2026-19274 | CRITICAL | 9.6 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another … | Sep 04, 2026 |
| CVE-2026-18905 | HIGH | 7.7 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding … | Sep 04, 2026 |
| CVE-2026-18887 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to … | Sep 04, 2026 |
| CVE-2026-18858 | LOW | 3.3 | IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. | Sep 04, 2026 |
| CVE-2026-18658 | CRITICAL | 9.8 | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements … | Sep 04, 2026 |