Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-7663 IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t… Langflow 1.10.0+ Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-13773EPSS 6% IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.… Websphere Extreme Scale after 8.6.1.6 Fix from $2,3002026-06-30 CRITICAL 9.9 CVE-2026-13772 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in… Websphere Extreme Scale after 8.6.1.6 Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-13449 IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML … Business Automation Manager 9.5.0+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-11714 IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-11712 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-11708 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-11546 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-… Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-10560 IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenti… Langflow after 1.9.6 Fix from $2,3002026-06-30 CRITICAL 9.6 CVE-2026-10140 IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-10134 IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat… Langflow after 1.9.3 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-10109 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling. Db2 after 12.1.4 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-58138EPSS 9% Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitra… Patch available Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-58172 Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based ac… Patch available Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-58166 OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write… Patch available Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-48315 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-48313 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48286 Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi… Campaign after 7.4.3 Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48283 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48281 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48277 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48276 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48282 KEVEPSS 42% ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-14241 Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of… Firefox Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-8655 Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service … Netscaler Application Delivery Controller 13.1-37.272 / 13.1-63.18+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-8452 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applian… Netscaler Application Delivery Controller 13.1-37.272 / 13.1-63.18+ Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-6556 @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string … Fastify\/express 4.0.7+ Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-58016 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo… Enterprise Linux 2.88.1+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-8402 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer In… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-53690 An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The ap… Mitigation only Fix from $2,3002026-06-30