Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-10545 IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w… Planning Analytics Local after 2.1.21 Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-10535 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. Db2 12.1.5+ Fix from $1,9502026-07-30 MEDIUM 5.5 CVE-2025-36374 IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2025-0152 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site… Engineering Requirements Management Doors Web Access after 9.7.2.11 Fix from $1,6002026-07-30 MEDIUM 6.3 CVE-2024-40683 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.… Operations Analytics Log Analysis after 1.3.8.4 Fix from $1,6002026-07-30 HIGH 7.5 CVE-2024-25039 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of … Engineering Requirements Management Doors Web Access after 9.7.2.11 Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-9322 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of … Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-30 MEDIUM 6.1 CVE-2026-66414 Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users … Patch available Fix from $1,6002026-07-30 MEDIUM 5.4 CVE-2026-54522 MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/bu… Messagepack 1.8.2+ Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-62663 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, doc… No fix yet Fix from $1,9502026-07-30 HIGH 8.7 CVE-2026-54722 DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts st… Patch available Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-51291 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-51290 SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-13379 The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras… Openvpn 2.7.5+ Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-13117 An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-12996 A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-12945 IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on … Langflow 1.10.2+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-12940 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C… Langflow 1.10.2+ Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-12932 A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.4 CVE-2026-11885 IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-11771 OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 MEDIUM 6.2 CVE-2026-67596 CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all st… No fix yet Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-58222 A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When… Mitigation only Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-58216 An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed… No fix yet Fix from $1,6002026-07-30 HIGH 8.5 CVE-2026-57862 Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-44617 LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters ins… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-44616 LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, al… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2026-44613 Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-4978 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL … No fix yet Fix from $2,3002026-07-30