CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2026-49102

    Last Modified: 27 May 2026

    Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

    Published: 27 May 2026
    6.1
    Medium

    CVE-2026-42184

    Last Modified: 2 Jun 2026

    Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI schemes directly. The issue is that Tauri's check to see if the origin is local, only checks the first subdomain of the URL. An attacker can abuse this by hosting a page on a domain whose subdomain matches the custom scheme of the application. This vulnerability is fixed in 2.10.3.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-48973

    Last Modified: 28 May 2026

    Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14.

    Published: 27 May 2026
    8.8
    High

    CVE-2026-44988

    Last Modified: 30 May 2026

    LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight rectangles whose width is larger than 2048 pixels. A malicious VNC server can send a crafted FramebufferUpdate rectangle using Tight encoding with NoZlib | ExplicitFilter and the Gradient filter. When a LibVNCClient-based client connects, the client processes the server-controlled rectangle width and writes beyond fixed-size Gradient buffers. This vulnerability is fixed with commit 5b270544b85233668b98161323297d418a8f5fd1.

    Published: 27 May 2026
    5.3
    Medium

    CVE-2026-47119

    Last Modified: 14 Jul 2026

    Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image_get API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. Attackers can place a crafted SVG file containing script tags in any path readable by the agent-zero process and lure an authenticated user to the image_get endpoint, causing the browser to execute the malicious script, steal the csrf_token cookie, and perform unauthorized API calls on behalf of the victim.

    Published: 27 May 2026
    8
    High

    CVE-2026-6957

    Last Modified: 2 Jun 2026

    Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filestore via a malicious filename delivered through the shared-channel attachment sync protocol. Mattermost Advisory ID: MMSA-2026-00659

    Published: 27 May 2026
    7.1
    High

    CVE-2026-47118

    Last Modified: 14 Jul 2026

    Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, which relies solely on an extension allowlist while the path containment check is explicitly disabled. Attackers can request any file with an image extension readable by the process, including files outside the agent workspace, user home directories, and mounted volumes, and can also leverage symlink-based escapes due to the lack of path canonicalization in the path resolution logic.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-1248

    Last Modified: 28 May 2026

    IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.

    Published: 27 May 2026
    8.7
    High

    CVE-2026-44830

    Last Modified: 29 May 2026

    Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware bypasses authentication for all HTTP requests. Combined with the default 0.0.0.0 host binding and CORS allow_origins=["*"], operators following the Docker setup without explicitly setting API_TOKEN expose the full Knowledge-Graph read/write API to any LAN-reachable client. An attacker on the same network can read, write, or delete all memory entries — including system://boot and core://* URIs that auto-load into downstream agent sessions, enabling persistent prompt-injection. This vulnerability is fixed in 2.4.1.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-9674

    Last Modified: 30 May 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.

    Published: 27 May 2026
    5.5
    Medium

    CVE-2026-48927

    Last Modified: 30 May 2026

    Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-48926

    Last Modified: 2 Jun 2026

    Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-48925

    Last Modified: 30 May 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-48924

    Last Modified: 30 May 2026

    Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

    Published: 27 May 2026
    4.3
    Medium

    CVE-2026-48923

    Last Modified: 30 May 2026

    Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.

    Published: 27 May 2026
    7.5
    High

    CVE-2026-48922

    Last Modified: 18 Jun 2026

    Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

    Published: 27 May 2026
    7.5
    High

    CVE-2026-48921

    Last Modified: 30 May 2026

    Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

    Published: 27 May 2026
    8.8
    High

    CVE-2026-48920

    Last Modified: 30 May 2026

    Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.

    Published: 27 May 2026
    6.6
    Medium

    CVE-2026-48919

    Last Modified: 18 Jun 2026

    Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

    Published: 27 May 2026
    6.6
    Medium

    CVE-2026-48918

    Last Modified: 30 May 2026

    Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

    Published: 27 May 2026
    6.6
    Medium

    CVE-2026-48917

    Last Modified: 18 Jun 2026

    Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

    Published: 27 May 2026
    6.6
    Medium

    CVE-2026-48916

    Last Modified: 2 Jun 2026

    Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.

    Published: 27 May 2026
    9.1
    Critical

    CVE-2026-7876

    Last Modified: 11 Jun 2026

    IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.

    Published: 27 May 2026
    8.4
    High

    CVE-2026-7365

    Last Modified: 2 Jun 2026

    IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

    Published: 27 May 2026
    6.8
    Medium

    CVE-2026-9617

    Last Modified: 2 Jun 2026

    PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed with superuser privileges. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version. With PostgreSQL 15 and later, the creation permission on the public schema is revoked by default and this exploit can only be achieved by a user who was explicitly granted the CREATE TABLE privilege. The problem is resolved in PostgreSQL Anonymizer 3.1.0 and further versions

    Published: 27 May 2026
    7.2
    High

    CVE-2024-56462

    Last Modified: 5 Jun 2026

    IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.

    Published: 27 May 2026
    5.9
    Medium

    CVE-2024-40684

    Last Modified: 5 Jun 2026

    IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

    Published: 27 May 2026
    5.3
    Medium

    CVE-2024-28765

    Last Modified: 3 Jun 2026

    IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-9035

    Last Modified: 5 Jun 2026

    IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.

    Published: 27 May 2026
    6.9
    Medium

    CVE-2026-23679

    Last Modified: 28 May 2026

    libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-8405

    Last Modified: 3 Jun 2026

    IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.

    Published: 27 May 2026
    5.1
    Medium

    CVE-2026-47104

    Last Modified: 28 May 2026

    libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service.

    Published: 27 May 2026
    7.5
    High

    CVE-2026-8180

    Last Modified: 5 Jun 2026

    IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.

    Published: 27 May 2026
    7.5
    High

    CVE-2026-48972

    Last Modified: 29 May 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion. This issue affects SeedProd Pro: from n/a before 6.19.5.

    Published: 27 May 2026
    8.8
    High

    CVE-2026-8179

    Last Modified: 5 Jun 2026

    IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.

    Published: 27 May 2026
    9.8
    Critical

    CVE-2026-8175

    Last Modified: 5 Jun 2026

    IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-7528

    Last Modified: 2 Jun 2026

    IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.

    Published: 27 May 2026
    9.8
    Critical

    CVE-2026-7524

    Last Modified: 2 Jun 2026

    IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

    Published: 27 May 2026
    5.3
    Medium

    CVE-2026-7254

    Last Modified: 2 Jun 2026

    IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-6938

    Last Modified: 28 May 2026

    IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-6936

    Last Modified: 28 May 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements.

    Published: 27 May 2026
    5.5
    Medium

    CVE-2026-6053

    Last Modified: 29 May 2026

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-6052

    Last Modified: 28 May 2026

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

    Published: 27 May 2026
    5.5
    Medium

    CVE-2026-6051

    Last Modified: 28 May 2026

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.

    Published: 27 May 2026
    4.4
    Medium

    CVE-2026-5516

    Last Modified: 2 Jun 2026

    IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.

    Published: 27 May 2026
    5.5
    Medium

    CVE-2026-5515

    Last Modified: 2 Jun 2026

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

    Published: 27 May 2026
    8.8
    High

    CVE-2026-5065

    Last Modified: 2 Jun 2026

    IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

    Published: 27 May 2026
    4.8
    Medium

    CVE-2026-4410

    Last Modified: 1 Jun 2026

    IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-3676

    Last Modified: 2 Jun 2026

    IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.

    Published: 27 May 2026
    6.8
    Medium

    CVE-2026-9704

    Last Modified: 26 Jun 2026

    A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This allows the user to gain the permissions of the client's service account, leading to privilege escalation.

    Published: 27 May 2026