Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48678
Total
3911
Critical
14443
High
14141
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19654 | HIGH | 7.5 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery … | Aug 12, 2026 |
| CVE-2026-19503 | MEDIUM | 4.8 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's … | Aug 12, 2026 |
| CVE-2026-19502 | MEDIUM | 5.5 | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain … | Aug 12, 2026 |
| CVE-2026-19130 | MEDIUM | 5.8 | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior … | Aug 12, 2026 |
| CVE-2026-19004 | HIGH | 8.1 | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue … | Aug 12, 2026 |
| CVE-2026-19002 | HIGH | 8.1 | A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the … | Aug 12, 2026 |
| CVE-2026-19001 | CRITICAL | 9.8 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or … | Aug 12, 2026 |
| CVE-2026-18888 | MEDIUM | 6.5 | The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an … | Aug 12, 2026 |
| CVE-2026-18097 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain … | Aug 12, 2026 |
| CVE-2026-18096 | LOW | 3.3 | IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to … | Aug 12, 2026 |
| CVE-2026-17616 | MEDIUM | 6.8 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse … | Aug 12, 2026 |
| CVE-2026-16695 | HIGH | 7.8 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used … | Aug 12, 2026 |
| CVE-2026-16480 | MEDIUM | 4.3 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to … | Aug 12, 2026 |
| CVE-2026-16033 | HIGH | 8.5 | A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD … | Aug 12, 2026 |
| CVE-2026-14866 | HIGH | 7.7 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. | Aug 12, 2026 |
| CVE-2026-13622 | HIGH | 8.8 | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ … | Aug 12, 2026 |
| CVE-2026-13476 | HIGH | 7.3 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due … | Aug 12, 2026 |
| CVE-2026-13433 | HIGH | 8.3 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A … | Aug 12, 2026 |
| CVE-2026-13367 | HIGH | 7.8 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. | Aug 12, 2026 |
| CVE-2026-13105 | HIGH | 8.8 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. | Aug 12, 2026 |
| CVE-2026-13094 | HIGH | 7.8 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable … | Aug 12, 2026 |
| CVE-2026-11932 | MEDIUM | 5.3 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is … | Aug 12, 2026 |
| CVE-2026-10543 | HIGH | 8.2 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. | Aug 12, 2026 |
| CVE-2026-73434 | MEDIUM | 6.1 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by … | Aug 12, 2026 |
| CVE-2026-73433 | MEDIUM | 6.6 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets … | Aug 12, 2026 |