Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2025-36220 — Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
6.1 MEDIUM
CVE-2025-36148 — IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to …

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allo…

May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.4 MEDIUM
CVE-2025-36145 — Multiple Vulnerabilities in watsonx.data

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.

watsonx.data watsonxdata | Remote | Misconfiguration
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
7.6 HIGH
CVE-2025-36126 — IBM Cognos Analytics is affected by Cross-site scripting.

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows…

cognos_analytics cognos_transformer | Remote | Cross-Site Scripting
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.4 MEDIUM
CVE-2025-14290 — IBM webMethods Integration Sever is vulnerable to server-side request forgery

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). Th…

May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.5 MEDIUM
CVE-2025-13755 — IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcas…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local …

db2 | Information Disclosure
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
8.1 HIGH
CVE-2026-48692 — FastNetMon Community Edition Unauthenticated gRPC API Remote Code Execution and Privilege…

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.c…

fastnetmon | Authentication
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
7.5 HIGH
CVE-2026-48688 — FastNetMon Community Edition BGP MP_REACH_NLRI IPv6 Attribute Decoder Out-of-Bounds Read …

FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains …

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-48687 — FastNetMon Juniper Router Integration OS Command Injection

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (l…

fastnetmon | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-48686 — FastNetMon Community Edition Buffer Overflow Vulnerability

FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() …

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-48685 — FastNetMon BGP Path Attribute Out-of-Bounds Memory Access Vulnerability

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_…

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-48684 — FastNetMon Community Edition Out-of-Bounds Read Vulnerability

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.…

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-48683 — FastNetMon Community Edition Out-of-Bounds Read Vulnerability

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template bra…

Remote | Information Disclosure
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-46620 — e107: CSRF in comment.php moderation endpoints via token-optional validation in session_h…

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check…

e107 | Remote | Cross-Site Request Forgery
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
4.3 MEDIUM
CVE-2026-43936 — e107: Server-Side Request Forgery (SSRF) in the remote file fetcher

e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "M…

e107 | Remote | Path Traversal
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.1 HIGH
CVE-2026-43935 — e107: Host Header Injection in e107 password reset enables phishing

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset l…

e107 | Remote | Misconfiguration
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-43934 — e107: Broken Access Control in e107 comment edit allows cross-user comment modification

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by othe…

e107 | Remote | Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-40564 — Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Ku…

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so th…

flink_kubernetes_operator | Remote | Server-Side Request Forgery
May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
4.3 MEDIUM
CVE-2026-38587 — ONLYOFFICE DocSpace IDOR Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-l…

Remote | Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.8 HIGH
CVE-2026-25112 — Genetec RabbitMQ Privilege Escalation Vulnerability

A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

| Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
Showing 20 of 6906 Results