Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50589
Total
4065
Critical
14978
High
14744
Medium
CVE ID Severity Score Description Published
CVE-2026-10700 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} … Jul 30, 2026
CVE-2026-10695 MEDIUM 6.2 IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries. Jul 30, 2026
CVE-2026-10545 HIGH 7.5 IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via … Jul 30, 2026
CVE-2026-10535 HIGH 8.4 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. Jul 30, 2026
CVE-2025-36374 MEDIUM 5.5 IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to … Jul 30, 2026
CVE-2025-0152 MEDIUM 6.1 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an … Jul 30, 2026
CVE-2024-40683 MEDIUM 6.3 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session … Jul 30, 2026
CVE-2024-25039 HIGH 7.5 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which … Jul 30, 2026
CVE-2026-9322 HIGH 7.5 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via … Jul 30, 2026
CVE-2026-66414 MEDIUM 6.1 Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating … Jul 30, 2026
CVE-2026-62663 HIGH 7.5 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks … Jul 30, 2026
CVE-2026-54722 UNKNOWN — DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the … Jul 30, 2026
CVE-2026-54522 UNKNOWN — MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after … Jul 30, 2026
CVE-2026-51295 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 30, 2026
CVE-2026-51294 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 30, 2026
CVE-2026-51293 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 30, 2026
CVE-2026-51292 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 30, 2026
CVE-2026-51291 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 30, 2026
CVE-2026-51290 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 30, 2026
CVE-2026-13379 UNKNOWN — The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted … Jul 30, 2026
CVE-2026-13117 UNKNOWN — An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially … Jul 30, 2026
CVE-2026-12996 UNKNOWN — A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory … Jul 30, 2026
CVE-2026-12945 HIGH 7.1 IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and … Jul 30, 2026
CVE-2026-12940 CRITICAL 9.8 IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. … Jul 30, 2026
CVE-2026-12932 UNKNOWN — A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial … Jul 30, 2026