Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47022
Total
3783
Critical
14020
High
13725
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-27871 | UNKNOWN | — | Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63. | Aug 14, 2026 |
| CVE-2026-19910 | HIGH | 7.5 | PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of … | Aug 14, 2026 |
| CVE-2026-19909 | HIGH | 7.5 | PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of … | Aug 14, 2026 |
| CVE-2026-19908 | HIGH | 7.1 | PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX … | Aug 14, 2026 |
| CVE-2026-18554 | HIGH | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a … | Aug 14, 2026 |
| CVE-2026-18178 | MEDIUM | 5.4 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. | Aug 14, 2026 |
| CVE-2026-17227 | MEDIUM | 5.4 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special … | Aug 14, 2026 |
| CVE-2026-17209 | MEDIUM | 6.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. | Aug 14, 2026 |
| CVE-2026-17186 | CRITICAL | 9.9 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special … | Aug 14, 2026 |
| CVE-2026-17184 | CRITICAL | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name … | Aug 14, 2026 |
| CVE-2026-17182 | CRITICAL | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to … | Aug 14, 2026 |
| CVE-2026-17181 | CRITICAL | 9.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. | Aug 14, 2026 |
| CVE-2026-17179 | HIGH | 8.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection. | Aug 14, 2026 |
| CVE-2026-17177 | HIGH | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. | Aug 14, 2026 |
| CVE-2026-17175 | HIGH | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. | Aug 14, 2026 |
| CVE-2026-17173 | MEDIUM | 6.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file … | Aug 14, 2026 |
| CVE-2026-17081 | HIGH | 8.2 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname … | Aug 14, 2026 |
| CVE-2026-17079 | MEDIUM | 6.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable … | Aug 14, 2026 |
| CVE-2026-16915 | HIGH | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. | Aug 14, 2026 |
| CVE-2026-16905 | MEDIUM | 5.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. | Aug 14, 2026 |
| CVE-2026-16879 | HIGH | 8.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied … | Aug 14, 2026 |
| CVE-2026-16708 | HIGH | 8.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. | Aug 14, 2026 |
| CVE-2026-73679 | HIGH | 7.2 | ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a … | Aug 14, 2026 |
| CVE-2026-73678 | CRITICAL | 10.0 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting … | Aug 14, 2026 |
| CVE-2026-50029 | MEDIUM | 5.3 | js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if … | Aug 14, 2026 |