Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 2,301 - 2,320 of 13,436 CVEs
CVE-2026-1248 MEDIUM - 4.3

IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.

Vendor: ibm
Product: business_automation_workflow
Published: May 27, 2026
Source: NVD
CVE-2026-9704 MEDIUM - 6.8

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client cre...

Vendor: redhat
Product: build_of_keycloak
Published: May 27, 2026
Source: NVD
CVE-2026-9617 MEDIUM - 6.8

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed with superuser privileges. The risk is higher with P...

Vendor: dalibo
Product: anonymizer
Published: May 27, 2026
Source: NVD
CVE-2026-9035 MEDIUM - 6.5

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able ...

Published: May 27, 2026
Source: NVD
CVE-2026-8405 MEDIUM - 6.5

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.

Vendor: ibm
Product: guardium_data_protection
Published: May 27, 2026
Source: NVD
CVE-2026-7254 MEDIUM - 5.3

IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.

Vendor: ibm
Product: openbmc
Published: May 27, 2026
Source: NVD
CVE-2026-6938 MEDIUM - 6.5

IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.

Vendor: ibm
Product: db2
Published: May 27, 2026
Source: NVD
CVE-2026-6936 MEDIUM - 6.5

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of stat...

Vendor: ibm
Product: i
Published: May 27, 2026
Source: NVD
CVE-2026-6053 MEDIUM - 5.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.

Vendor: ibm
Product: db2
Published: May 27, 2026
Source: NVD
CVE-2026-6052 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

Vendor: ibm
Product: db2
Published: May 27, 2026
Source: NVD
CVE-2026-6051 MEDIUM - 5.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.

Vendor: ibm
Product: db2
Published: May 27, 2026
Source: NVD
CVE-2026-5516 MEDIUM - 4.4

IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.

Vendor: ibm
Product: websphere_application_server
Published: May 27, 2026
Source: NVD
CVE-2026-5515 MEDIUM - 5.5

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

Vendor: ibm
Product: app_connect_enterprise
Published: May 27, 2026
Source: NVD
CVE-2026-4410 MEDIUM - 4.8

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to ...

Vendor: ibm
Product: websphere_application_server
Published: May 27, 2026
Source: NVD
CVE-2026-48971 MEDIUM - 4.3

Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6.

Vendor: WebToffee
Product: Product Import Export for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-47104 MEDIUM - 4.0

libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer...

Vendor: libusb
Product: libusb
Published: May 27, 2026
Source: NVD
CVE-2026-3676 MEDIUM - 6.5

IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced enviro...

Vendor: ibm
Product: cloud_application_performance_managemen
Published: May 27, 2026
Source: NVD
CVE-2026-2607 MEDIUM - 5.1

IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.6 through r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2...

Published: May 27, 2026
Source: NVD
CVE-2026-2340 MEDIUM - 6.5

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share c...

Vendor: redhat
Product: openshift_container_platform
Published: May 27, 2026
Source: NVD
CVE-2026-23679 MEDIUM - 6.2

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exce...

Vendor: libusb
Product: libusb
Published: May 27, 2026
Source: NVD