Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28489
Total
2193
Critical
8545
High
8865
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-35223 | UNKNOWN | — | An improper access check allows unauthorized access to com_config webservice endpoints. | May 26, 2026 |
| CVE-2026-35222 | CRITICAL | 9.8 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | May 26, 2026 |
| CVE-2026-35221 | CRITICAL | 9.8 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | May 26, 2026 |
| CVE-2026-35220 | MEDIUM | 4.3 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. | May 26, 2026 |
| CVE-2026-30895 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | May 26, 2026 |
| CVE-2026-30894 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the content history component. | May 26, 2026 |
| CVE-2026-2264 | UNKNOWN | — | A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For … | May 26, 2026 |
| CVE-2026-25901 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | May 26, 2026 |
| CVE-2026-25900 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the feed modules. | May 26, 2026 |
| CVE-2026-24212 | HIGH | 7.5 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to … | May 26, 2026 |
| CVE-2026-24162 | HIGH | 7.8 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead … | May 26, 2026 |
| CVE-2025-36221 | MEDIUM | 5.3 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from … | May 26, 2026 |
| CVE-2025-36220 | MEDIUM | 4.3 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A … | May 26, 2026 |
| CVE-2025-36148 | MEDIUM | 5.4 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows … | May 26, 2026 |
| CVE-2025-36145 | MEDIUM | 5.4 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files … | May 26, 2026 |
| CVE-2025-36126 | MEDIUM | 6.4 | IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. … | May 26, 2026 |
| CVE-2025-14290 | MEDIUM | 5.4 | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow … | May 26, 2026 |
| CVE-2025-13755 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files … | May 26, 2026 |
| CVE-2026-48692 | HIGH | 8.1 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line … | May 26, 2026 |
| CVE-2026-48688 | HIGH | 7.5 | FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment … | May 26, 2026 |
| CVE-2026-48687 | UNKNOWN | — | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs … | May 26, 2026 |
| CVE-2026-48686 | CRITICAL | 9.8 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in src/bgp_protocol.cpp reads … | May 26, 2026 |
| CVE-2026-48685 | MEDIUM | 6.5 | FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the … | May 26, 2026 |
| CVE-2026-48684 | MEDIUM | 6.5 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.cpp), the scope parsing loop (lines 224-229) … | May 26, 2026 |
| CVE-2026-48683 | MEDIUM | 6.5 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) … | May 26, 2026 |