Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51159
Total
4081
Critical
15166
High
14812
Medium
CVE ID Severity Score Description Published
CVE-2026-54621 HIGH 7.8 datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja2 are rendered into Python comments without … Jul 28, 2026
CVE-2026-6881 UNKNOWN — A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases … Jul 28, 2026
CVE-2026-59943 UNKNOWN — Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by … Jul 28, 2026
CVE-2026-59942 UNKNOWN — Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. … Jul 28, 2026
CVE-2026-59941 UNKNOWN — Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on … Jul 28, 2026
CVE-2026-56722 UNKNOWN — Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction … Jul 28, 2026
CVE-2026-49447 MEDIUM 5.3 Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In … Jul 28, 2026
CVE-2026-16581 MEDIUM 5.3 In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to … Jul 28, 2026
CVE-2026-15328 HIGH 7.4 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. Jul 28, 2026
CVE-2026-15325 HIGH 8.7 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to … Jul 28, 2026
CVE-2026-15280 HIGH 7.5 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism. Jul 28, 2026
CVE-2026-15064 HIGH 8.7 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to … Jul 28, 2026
CVE-2026-15057 HIGH 7.5 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. Jul 28, 2026
CVE-2026-14996 HIGH 8.2 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. Jul 28, 2026
CVE-2026-14981 HIGH 7.5 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability … Jul 28, 2026
CVE-2026-14976 HIGH 7.1 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. Jul 28, 2026
CVE-2026-14974 HIGH 8.1 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. Jul 28, 2026
CVE-2026-14973 CRITICAL 9.3 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. Jul 28, 2026
CVE-2026-14959 CRITICAL 9.1 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. Jul 28, 2026
CVE-2026-14958 CRITICAL 9.1 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. Jul 28, 2026
CVE-2026-14893 HIGH 7.3 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration … Jul 28, 2026
CVE-2026-14528 HIGH 7.4 IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. Jul 28, 2026
CVE-2026-14515 MEDIUM 6.1 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. Jul 28, 2026
CVE-2026-14512 CRITICAL 9.8 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute … Jul 28, 2026
CVE-2026-14446 CRITICAL 9.8 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. Jul 28, 2026