Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50589
Total
4065
Critical
14978
High
14744
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10700 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} … | Jul 30, 2026 |
| CVE-2026-10695 | MEDIUM | 6.2 | IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries. | Jul 30, 2026 |
| CVE-2026-10545 | HIGH | 7.5 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via … | Jul 30, 2026 |
| CVE-2026-10535 | HIGH | 8.4 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. | Jul 30, 2026 |
| CVE-2025-36374 | MEDIUM | 5.5 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to … | Jul 30, 2026 |
| CVE-2025-0152 | MEDIUM | 6.1 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an … | Jul 30, 2026 |
| CVE-2024-40683 | MEDIUM | 6.3 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session … | Jul 30, 2026 |
| CVE-2024-25039 | HIGH | 7.5 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which … | Jul 30, 2026 |
| CVE-2026-9322 | HIGH | 7.5 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via … | Jul 30, 2026 |
| CVE-2026-66414 | MEDIUM | 6.1 | Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating … | Jul 30, 2026 |
| CVE-2026-62663 | HIGH | 7.5 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks … | Jul 30, 2026 |
| CVE-2026-54722 | UNKNOWN | — | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the … | Jul 30, 2026 |
| CVE-2026-54522 | UNKNOWN | — | MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after … | Jul 30, 2026 |
| CVE-2026-51295 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … | Jul 30, 2026 |
| CVE-2026-51294 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … | Jul 30, 2026 |
| CVE-2026-51293 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … | Jul 30, 2026 |
| CVE-2026-51292 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … | Jul 30, 2026 |
| CVE-2026-51291 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … | Jul 30, 2026 |
| CVE-2026-51290 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … | Jul 30, 2026 |
| CVE-2026-13379 | UNKNOWN | — | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted … | Jul 30, 2026 |
| CVE-2026-13117 | UNKNOWN | — | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially … | Jul 30, 2026 |
| CVE-2026-12996 | UNKNOWN | — | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory … | Jul 30, 2026 |
| CVE-2026-12945 | HIGH | 7.1 | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and … | Jul 30, 2026 |
| CVE-2026-12940 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. … | Jul 30, 2026 |
| CVE-2026-12932 | UNKNOWN | — | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial … | Jul 30, 2026 |