Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50855
Total
4075
Critical
15116
High
14809
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59941 | UNKNOWN | — | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on … | Jul 28, 2026 |
| CVE-2026-56722 | UNKNOWN | — | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction … | Jul 28, 2026 |
| CVE-2026-49447 | MEDIUM | 5.3 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In … | Jul 28, 2026 |
| CVE-2026-16581 | MEDIUM | 5.3 | In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to … | Jul 28, 2026 |
| CVE-2026-15328 | HIGH | 7.4 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. | Jul 28, 2026 |
| CVE-2026-15325 | HIGH | 8.7 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to … | Jul 28, 2026 |
| CVE-2026-15280 | HIGH | 7.5 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism. | Jul 28, 2026 |
| CVE-2026-15064 | HIGH | 8.7 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to … | Jul 28, 2026 |
| CVE-2026-15057 | HIGH | 7.5 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. | Jul 28, 2026 |
| CVE-2026-14996 | HIGH | 8.2 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. | Jul 28, 2026 |
| CVE-2026-14981 | HIGH | 7.5 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability … | Jul 28, 2026 |
| CVE-2026-14976 | HIGH | 7.1 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. | Jul 28, 2026 |
| CVE-2026-14974 | HIGH | 8.1 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. | Jul 28, 2026 |
| CVE-2026-14973 | CRITICAL | 9.3 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | Jul 28, 2026 |
| CVE-2026-14959 | CRITICAL | 9.1 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. | Jul 28, 2026 |
| CVE-2026-14958 | CRITICAL | 9.1 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. | Jul 28, 2026 |
| CVE-2026-14893 | HIGH | 7.3 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration … | Jul 28, 2026 |
| CVE-2026-14528 | HIGH | 7.4 | IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. | Jul 28, 2026 |
| CVE-2026-14515 | MEDIUM | 6.1 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. | Jul 28, 2026 |
| CVE-2026-14512 | CRITICAL | 9.8 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute … | Jul 28, 2026 |
| CVE-2026-14446 | CRITICAL | 9.8 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | Jul 28, 2026 |
| CVE-2026-13463 | HIGH | 7.5 | IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. | Jul 28, 2026 |
| CVE-2026-13442 | HIGH | 7.1 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query … | Jul 28, 2026 |
| CVE-2026-57511 | MEDIUM | 5.4 | SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event … | Jul 28, 2026 |
| CVE-2026-57510 | HIGH | 8.8 | SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to … | Jul 28, 2026 |