Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-6327 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

concert | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-93769 — HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading t…

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inj…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
2.7 LOW
CVE-2026-4921 — IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used…

guardium_data_protection | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-3626 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in fur…

concert | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.2 MEDIUM
CVE-2026-19267 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor c…

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-19179 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.4 MEDIUM
CVE-2026-19087 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.3 HIGH
CVE-2026-18875 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An un…

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.3 CRITICAL
CVE-2026-18872 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42)…

| Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.4 MEDIUM
CVE-2026-18505 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a reques…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-18490 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoi…

| Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.3 HIGH
CVE-2026-18185 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critica…

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.4 HIGH
CVE-2026-18184 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.

| XML External Entity
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.1 HIGH
CVE-2026-18181 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-18180 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.8 MEDIUM
CVE-2026-96675 — alsa-lib through 1.2.16.1 Denial of Service via pcm_multi

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA c…

| Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.8 MEDIUM
CVE-2026-96674 — alsa-lib through 1.2.16.1 Integer Overflow via Topology File

alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted top…

| Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.7 HIGH
CVE-2026-96673 — Photoview through 2.4.0 SQL Injection via album download route

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers ca…

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.4 MEDIUM
CVE-2026-96672 — Frappe ERPNext before 16.34.1 Unauthorized Method Invocation

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers…

erpnext | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.9 MEDIUM
CVE-2026-96611 — FFmpeg Signed Integer Overflow

FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds ch…

ffmpeg | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14295 Results