Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-18140 Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes fr… Aws Smithy Json 0.62.7+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-15978 SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote at… Sglang after 0.5.15 Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-15977 SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the… Sglang after 0.5.15 Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-15976 SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from… Sglang after 0.5.15 Fix from $2,3002026-07-30 MEDIUM 6.5 CVE-2026-15974 SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access … Sglang after 0.5.15 Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-15971 SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena… Sglang after 0.5.15 Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15969 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma… Sglang after 0.5.15 Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-13444 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matchin… Langflow 1.10.2+ Fix from $1,9502026-07-30 CRITICAL 9.9 CVE-2026-13435 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. Langflow 1.10.2+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12943 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)… Hardware Management Console 10.3.1064.1 / 11.1.1112.1+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-12942 IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted… Langflow 1.10.2+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-12733 IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. Datapower Gateway 10.5.0.22 / 10.6.0.10+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-12118 IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d… Webmethods Integration No fix yet Fix from $2,3002026-07-30 MEDIUM 5.3 CVE-2026-11904 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr… Verify Identity Access after 11.0.2 Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-10700 IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access … Langflow 1.9.0+ Fix from $1,6002026-07-30 MEDIUM 5.5 CVE-2026-10695 IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries. Db2 12.1.5+ Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-10545 IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w… Planning Analytics Local after 2.1.21 Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-10535 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. Db2 12.1.5+ Fix from $1,9502026-07-30 MEDIUM 5.5 CVE-2025-36374 IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2025-0152 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site… Engineering Requirements Management Doors Web Access after 9.7.2.11 Fix from $1,6002026-07-30 MEDIUM 6.3 CVE-2024-40683 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.… Operations Analytics Log Analysis after 1.3.8.4 Fix from $1,6002026-07-30 HIGH 7.5 CVE-2024-25039 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of … Engineering Requirements Management Doors Web Access after 9.7.2.11 Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-9322 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of … Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-30 MEDIUM 6.1 CVE-2026-66414 Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users … Patch available Fix from $1,6002026-07-30 MEDIUM 5.4 CVE-2026-54522 MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/bu… Messagepack 1.8.2+ Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-62663 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, doc… No fix yet Fix from $1,9502026-07-30 HIGH 8.7 CVE-2026-54722 DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts st… Patch available Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-51291 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-51290 SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-13379 The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras… Openvpn 2.7.5+ Fix from $2,3002026-07-30