Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-82094 | HIGH | 7.1 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a … | |
| CVE-2026-82093 | HIGH | 8.8 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | |
| CVE-2026-81552 | HIGH | 8.8 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | |
| CVE-2026-81549 | CRITICAL | 9.6 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | |
| CVE-2026-81548 | HIGH | 8.8 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements use… | |
| CVE-2026-81547 | HIGH | 8.8 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. | |
| CVE-2026-81545 | HIGH | 8.8 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements use… | |
| CVE-2026-81539 | HIGH | 8.8 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in… | |
| CVE-2026-77874 | HIGH | 8.6 | 2026-09-24 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specia… | |
| CVE-2026-77825 | MEDIUM | 4.9 | 2026-09-24 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement c… | |
| CVE-2026-77707 | MEDIUM | Patched | 5.9 | 2026-09-24 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 … |
| CVE-2026-77703 | MEDIUM | Patched | 5.9 | 2026-09-24 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine… |
| CVE-2026-73064 | LOW | 2.9 | 2026-09-24 | In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. Thi… | |
| CVE-2026-6544 | MEDIUM | 6.2 | 2026-09-24 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files … | |
| CVE-2026-65422 | MEDIUM | 6.5 | 2026-09-24 | A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails. | |
| CVE-2026-58008 | HIGH | 8.1 | 2026-09-24 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affe… | |
| CVE-2026-58007 | HIGH | 8.1 | 2026-09-24 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue af… | |
| CVE-2026-58006 | HIGH | 8.1 | 2026-09-24 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue af… | |
| CVE-2026-58005 | HIGH | 8.1 | 2026-09-24 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| CVE-2026-58004 | HIGH | 8.1 | 2026-09-24 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| CVE-2026-56736 | HIGH | 8.2 | 2026-09-24 | phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-p… | |
| CVE-2026-52001 | NONE | — | 2026-09-24 | An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts | |
| CVE-2026-51997 | NONE | — | 2026-09-24 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions | |
| CVE-2026-51996 | NONE | — | 2026-09-24 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function | |
| CVE-2026-51995 | HIGH | 7.5 | 2026-09-24 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils… |