Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28442
Total
2191
Critical
8537
High
8856
Medium
CVE ID Severity Score Description Published
CVE-2026-9035 MEDIUM 6.5 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026
CVE-2026-8405 MEDIUM 6.5 IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug … May 27, 2026
CVE-2026-8180 HIGH 7.5 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026
CVE-2026-8179 HIGH 8.8 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026
CVE-2026-8175 CRITICAL 9.8 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026
CVE-2026-7876 UNKNOWN IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 May 27, 2026
CVE-2026-7528 HIGH 7.1 IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption. May 27, 2026
CVE-2026-7524 CRITICAL 9.8 IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction. May 27, 2026
CVE-2026-7365 HIGH 8.4 IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during … May 27, 2026
CVE-2026-7254 MEDIUM 5.3 IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users. May 27, 2026
CVE-2026-6938 MEDIUM 6.5 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. May 27, 2026
CVE-2026-6936 MEDIUM 6.5 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An … May 27, 2026
CVE-2026-6053 MEDIUM 5.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range … May 27, 2026
CVE-2026-6052 MEDIUM 6.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. May 27, 2026
CVE-2026-6051 MEDIUM 5.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small … May 27, 2026
CVE-2026-5516 MEDIUM 4.4 IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions … May 27, 2026
CVE-2026-5515 MEDIUM 5.5 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. May 27, 2026
CVE-2026-5065 HIGH 8.8 IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, … May 27, 2026
CVE-2026-4410 MEDIUM 4.8 IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to … May 27, 2026
CVE-2026-48972 HIGH 7.5 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion. … May 27, 2026
CVE-2026-48971 MEDIUM 4.3 Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for … May 27, 2026
CVE-2026-47104 MEDIUM 4.0 libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying … May 27, 2026
CVE-2026-46103 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix devres lifetime USB drivers bind to USB interfaces and any device managed … May 27, 2026
CVE-2026-46102 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abort_strp() When the stream parser is aborted, for example … May 27, 2026
CVE-2026-46101 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: netfilter: reject zero shift in nft_bitwise Reject zero shift operands for nft_bitwise left and right … May 27, 2026