Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28489
Total
2193
Critical
8545
High
8865
Medium
CVE ID Severity Score Description Published
CVE-2026-35223 UNKNOWN An improper access check allows unauthorized access to com_config webservice endpoints. May 26, 2026
CVE-2026-35222 CRITICAL 9.8 Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. May 26, 2026
CVE-2026-35221 CRITICAL 9.8 Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. May 26, 2026
CVE-2026-35220 MEDIUM 4.3 Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. May 26, 2026
CVE-2026-30895 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the readmore links for com_content. May 26, 2026
CVE-2026-30894 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the content history component. May 26, 2026
CVE-2026-2264 UNKNOWN A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For … May 26, 2026
CVE-2026-25901 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the multilingual associations component. May 26, 2026
CVE-2026-25900 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the feed modules. May 26, 2026
CVE-2026-24212 HIGH 7.5 NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to … May 26, 2026
CVE-2026-24162 HIGH 7.8 NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead … May 26, 2026
CVE-2025-36221 MEDIUM 5.3 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from … May 26, 2026
CVE-2025-36220 MEDIUM 4.3 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A … May 26, 2026
CVE-2025-36148 MEDIUM 5.4 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows … May 26, 2026
CVE-2025-36145 MEDIUM 5.4 IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files … May 26, 2026
CVE-2025-36126 MEDIUM 6.4 IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. … May 26, 2026
CVE-2025-14290 MEDIUM 5.4 IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow … May 26, 2026
CVE-2025-13755 MEDIUM 5.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files … May 26, 2026
CVE-2026-48692 HIGH 8.1 FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line … May 26, 2026
CVE-2026-48688 HIGH 7.5 FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment … May 26, 2026
CVE-2026-48687 UNKNOWN FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs … May 26, 2026
CVE-2026-48686 CRITICAL 9.8 FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in src/bgp_protocol.cpp reads … May 26, 2026
CVE-2026-48685 MEDIUM 6.5 FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the … May 26, 2026
CVE-2026-48684 MEDIUM 6.5 FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.cpp), the scope parsing loop (lines 224-229) … May 26, 2026
CVE-2026-48683 MEDIUM 6.5 FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) … May 26, 2026