Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-14981 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-14976 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e… Websphere Application Server 26.0.0.9+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14974 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.3 CVE-2026-14973 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. Aspera after 1.0.19 Fix from $2,3002026-07-28 HIGH 7.2 CVE-2026-14959 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-14958 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28 HIGH 7.3 CVE-2026-14893 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable t… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-14528 IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-28 MEDIUM 6.1 CVE-2026-14515 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,6002026-07-28 CRITICAL 9.8 CVE-2026-14512 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14446 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. Websphere Application Server 8.5.5.30 / 9.0.5.28+ Fix from $2,3002026-07-28 HIGH 7.5 CVE-2026-13463 IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. Cloud Pak System No fix yet Fix from $1,9502026-07-28 HIGH 7.1 CVE-2026-13442 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence… Langflow 1.10.2+ Fix from $1,9502026-07-28 MEDIUM 5.4 CVE-2026-57511 SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by in… Patch available Fix from $1,6002026-07-28 HIGH 8.8 CVE-2026-57510 SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated user… Patch available Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55555 Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the … Dompdf 3.16+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55554 Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() pref… Dompdf 3.1.6+ Fix from $1,9502026-07-28 HIGH 8.1 CVE-2026-48060 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in con… Mitigation only Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-16347 MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-16192 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feat… Websphere Application Server 26.0.0.9+ Fix from $1,6002026-07-28 CRITICAL 9.8 CVE-2026-16184 IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 MEDIUM 5.9 CVE-2026-16107 IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att… No fix yet Fix from $1,6002026-07-28 MEDIUM 6.3 CVE-2026-11391 Tanium addressed a SQL injection vulnerability in Patch. No fix yet Fix from $1,6002026-07-28 MEDIUM 6.5 CVE-2026-7362 IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2… Sterling B2b Integrator after 6.2.2.0_1 Fix from $1,6002026-07-28 HIGH 8.1 CVE-2026-7769 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0… Sterling B2b Integrator after 6.2.2.0_1 Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-66745 Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated at… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-59932 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through … Patch available Fix from $1,9502026-07-28 HIGH 7.7 CVE-2026-50738 A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has be… No fix yet Fix from $1,9502026-07-28 CRITICAL 9.0 CVE-2026-50737 When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the s… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.0 CVE-2026-50736 The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads… No fix yet Fix from $2,3002026-07-28