CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,655 result(s) · page 167 of 183
CVE-2026-19816
HIGH

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler i...

CVSS 7.1 2026-09-14
CVE-2026-19624
HIGH

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf fil...

CVSS 7.8 2026-09-14
CVE-2026-18119
CRITICAL

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. A...

CVSS 9 Concretecms concrete_cms 2026-09-14
CVE-2026-18065
MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

CVSS 5.3 2026-09-14
CVE-2026-17628
MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

CVSS 5.4 2026-09-14
CVE-2026-17467
HIGH

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.

CVSS 8.2 2026-09-14
CVE-2026-17463
MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of ...

CVSS 6.5 2026-09-14
CVE-2026-17416
HIGH

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

CVSS 7.8 2026-09-14
CVE-2026-17156
HIGH

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

CVSS 7.8 2026-09-14
CVE-2026-17133
HIGH

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of speci...

CVSS 7.8 2026-09-14
CVE-2026-17047
MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

CVSS 5.4 2026-09-14
CVE-2026-16702
MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of ...

CVSS 6.5 2026-09-14
CVE-2026-16673
HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special cha...

CVSS 8.8 2026-09-14
CVE-2026-16466
HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

CVSS 8.8 2026-09-14
CVE-2026-16435
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

CVSS 5.9 2026-09-14
CVE-2026-16432
HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external ent...

CVSS 7.7 2026-09-14
CVE-2026-16428
HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transforma...

CVSS 8.8 2026-09-14
CVE-2026-16338
CRITICAL

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

CVSS 9.9 2026-09-14
CVE-2026-16335
HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerabilit...

CVSS 8.1 2026-09-14
CVE-2026-16188
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

CVSS 5.3 2026-09-14
1 165 166 167 168 169 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.