Vulnerabilities (CVE)

Total 398493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-17079 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 6.3 MEDIUM
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
CVE-2026-17081 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 8.2 HIGH
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
CVE-2026-17173 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 6.5 MEDIUM
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
CVE-2026-17175 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 7.5 HIGH
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
CVE-2026-59939 1 Httplib2 Project 1 Httplib2 2026-08-20 N/A 7.5 HIGH
httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.
CVE-2026-17177 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 7.5 HIGH
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
CVE-2026-17179 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 8.5 HIGH
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
CVE-2026-17181 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 9.3 CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
CVE-2026-17182 1 Ibm 1 Db2 Mirror For I 2026-08-20 N/A 9.8 CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
CVE-2026-63723 2026-08-20 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60737 1 Oracle 1 Web Services Manager 2026-08-20 N/A 9.1 CRITICAL
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CVE-2025-12131 1 Silabs 1 Simplicity Software Development Kit 2026-08-20 N/A 6.5 MEDIUM
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
CVE-2026-74961 1 Mozilla 2 Firefox, Thunderbird 2026-08-20 N/A 9.1 CRITICAL
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74968 1 Mozilla 2 Firefox, Thunderbird 2026-08-20 N/A 5.4 MEDIUM
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74245 1 Redhat 2 Openshift Update Service, Quay 2026-08-20 N/A 5.9 MEDIUM
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.
CVE-2026-74244 1 Redhat 2 Openshift Update Service, Quay 2026-08-20 N/A 5.9 MEDIUM
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.
CVE-2026-74247 1 Redhat 2 Openshift Update Service, Quay 2026-08-20 N/A 4.2 MEDIUM
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.
CVE-2026-74979 1 Mozilla 2 Firefox, Thunderbird 2026-08-20 N/A 9.8 CRITICAL
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74243 1 Redhat 2 Openshift Update Service, Quay 2026-08-20 N/A 6.5 MEDIUM
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths. The primary consequence is worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.
CVE-2026-74240 1 Redhat 2 Openshift Update Service, Quay 2026-08-20 N/A 5.4 MEDIUM
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.