Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47870
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-19909 HIGH 7.5 PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of … Aug 14, 2026
CVE-2026-19908 HIGH 7.1 PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX … Aug 14, 2026
CVE-2026-18554 HIGH 7.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a … Aug 14, 2026
CVE-2026-18178 MEDIUM 5.4 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. Aug 14, 2026
CVE-2026-17227 MEDIUM 5.4 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special … Aug 14, 2026
CVE-2026-17209 MEDIUM 6.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. Aug 14, 2026
CVE-2026-17186 CRITICAL 9.9 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special … Aug 14, 2026
CVE-2026-17184 CRITICAL 9.8 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name … Aug 14, 2026
CVE-2026-17182 CRITICAL 9.8 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to … Aug 14, 2026
CVE-2026-17181 CRITICAL 9.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. Aug 14, 2026
CVE-2026-17179 HIGH 8.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection. Aug 14, 2026
CVE-2026-17177 HIGH 7.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. Aug 14, 2026
CVE-2026-17175 HIGH 7.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. Aug 14, 2026
CVE-2026-17173 MEDIUM 6.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file … Aug 14, 2026
CVE-2026-17081 HIGH 8.2 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname … Aug 14, 2026
CVE-2026-17079 MEDIUM 6.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable … Aug 14, 2026
CVE-2026-16915 HIGH 7.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. Aug 14, 2026
CVE-2026-16905 MEDIUM 5.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. Aug 14, 2026
CVE-2026-16879 HIGH 8.8 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied … Aug 14, 2026
CVE-2026-16708 HIGH 8.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. Aug 14, 2026
CVE-2026-73679 HIGH 7.2 ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a … Aug 14, 2026
CVE-2026-73678 CRITICAL 10.0 MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting … Aug 14, 2026
CVE-2026-50029 MEDIUM 5.3 js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if … Aug 14, 2026
CVE-2026-50027 CRITICAL 9.8 mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, … Aug 14, 2026
CVE-2026-49457 CRITICAL 9.1 erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The … Aug 14, 2026