Total
395675 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-82762 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82794 | 2026-09-16 | N/A | 8.8 HIGH | ||
| SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-80217 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands. | |||||
| CVE-2026-89156 | 1 Pcre | 1 Pcre2 | 2026-09-16 | N/A | 2.9 LOW |
| PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. | |||||
| CVE-2026-69646 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 8.3 HIGH |
| Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |||||
| CVE-2026-92126 | 2026-09-16 | N/A | N/A | ||
| Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on the classpath of the component that evaluates the script. | |||||
| CVE-2026-69642 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 6.5 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-89157 | 1 Pcre | 1 Pcre2 | 2026-09-16 | N/A | 5.7 MEDIUM |
| PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. | |||||
| CVE-2026-66308 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |||||
| CVE-2026-15412 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. | |||||
| CVE-2026-15634 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks. | |||||
| CVE-2026-12765 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |||||
| CVE-2026-15955 | 2026-09-16 | N/A | 7.5 HIGH | ||
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths. | |||||
| CVE-2026-18065 | 2026-09-16 | N/A | 5.3 MEDIUM | ||
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i. | |||||
| CVE-2026-12766 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |||||
| CVE-2026-16189 | 2026-09-16 | N/A | 4.8 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |||||
| CVE-2026-19280 | 2026-09-16 | N/A | 5.2 MEDIUM | ||
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. | |||||
| CVE-2026-12763 | 2026-09-16 | N/A | 4.2 MEDIUM | ||
| IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component. | |||||
| CVE-2026-78415 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup. | |||||
| CVE-2026-13265 | 2026-09-16 | N/A | 6.8 MEDIUM | ||
| IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API. | |||||
