Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Websphere Application Server HIGH 7.5
CVE-2026-14981

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…

Fix: 26.0.0.9+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Aspera CRITICAL 9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Fix: after 1.0.19
Fix from $2,300 2026-07-28
Aspera Faspex HIGH 7.2
CVE-2026-14959

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 7.2
CVE-2026-14958

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.3
CVE-2026-14893

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable t…

No fix yet
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-14528

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server MEDIUM 6.1
CVE-2026-14515

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,600 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $2,300 2026-07-28
Cloud Pak System HIGH 7.5
CVE-2026-13463

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

No fix yet
Fix from $1,950 2026-07-28
Langflow HIGH 7.1
CVE-2026-13442

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence…

Fix: 1.10.2+
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.4
CVE-2026-57511

SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by in…

Patch available
Fix from $1,600 2026-07-28
Unclassified HIGH 8.8
CVE-2026-57510

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated user…

Patch available
Fix from $1,950 2026-07-28
Dompdf HIGH 7.5
CVE-2026-55555

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the …

Fix: 3.16+
Fix from $1,950 2026-07-28
Dompdf HIGH 7.5
CVE-2026-55554

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() pref…

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.1
CVE-2026-48060

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in con…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system…

No fix yet
Fix from $1,950 2026-07-28
Websphere Application Server MEDIUM 6.5
CVE-2026-16192

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feat…

Fix: 26.0.0.9+
Fix from $1,600 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Unclassified MEDIUM 5.9
CVE-2026-16107

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.3
CVE-2026-11391

Tanium addressed a SQL injection vulnerability in Patch.

No fix yet
Fix from $1,600 2026-07-28
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-7362

IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2…

Fix: after 6.2.2.0_1
Fix from $1,600 2026-07-28
Sterling B2b Integrator HIGH 8.1
CVE-2026-7769

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0…

Fix: after 6.2.2.0_1
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-66745

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated at…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-59932

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.7
CVE-2026-50738

A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has be…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.0
CVE-2026-50737

When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the s…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.0
CVE-2026-50736

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads…

No fix yet
Fix from $2,300 2026-07-28