Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-4051 — IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth …

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.

engineering_lifecycle_management | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-48689 — FastNetMon Heap-Based Buffer Overflow Vulnerability

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer,…

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-3660 — IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication By…

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap…

engineering_lifecycle_management | Remote | Authentication
May 26, 2026 May 29, 2026
May 26, 2026
May 29, 2026
7.1 HIGH
CVE-2026-3603 — IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external enti…

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML exter…

engineering_lifecycle_management | Remote | XML External Entity
May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
3.3 LOW
CVE-2026-9567 — GPAC MP4Box isom_intern.c MergeFragment null pointer dereference

A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointe…

gpac | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9566 — teableio teable Sign-up LoginPage.tsx cross site scripting

A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipul…

teable | Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.4 CRITICAL
CVE-2026-9560 — OpenVPN Connect Privilege Escalation Vulnerability

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

connect | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-9170 — IBM HTTP Server is affected by multiple vulnerabilities

IBM HTTP Server 8.5, and 9.0

May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.1 CRITICAL
CVE-2026-8856 — IBM HTTP Server is affected by multiple vulnerabilities

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

linux_kernel aix windows http_server z\/os | Remote | Denial of Service
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-8855 — IBM HTTP Server is affected by multiple vulnerabilities

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

linux_kernel aix windows http_server z\/os | Remote | Denial of Service
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-8854 — IBM HTTP Server is affected by multiple vulnerabilities

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

linux_kernel aix windows http_server z\/os | Remote | Denial of Service
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.3 HIGH
CVE-2026-8835 — IBM HTTP Server is affected by multiple vulnerabilities

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive informat…

linux_kernel aix windows http_server z\/os | Information Disclosure
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.0 HIGH
CVE-2026-8834 — IBM HTTP Server is affected by multiple vulnerabilities

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause …

linux_kernel aix windows http_server z\/os | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-8633 — IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by…

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code executi…

May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
7.5 HIGH
CVE-2026-8620 — IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by…

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggl…

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
7.8 HIGH
CVE-2026-7454 — WRL File Parsing Memory Corruption in Autodesk 3ds Max

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…

3ds_max | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.5 MEDIUM
CVE-2026-7453 — WRL File Parsing Memory Exhaustion in Autodesk 3ds Max

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.

3ds_max | Denial of Service
May 26, 2026 Jun 03, 2026
May 26, 2026
Jun 03, 2026
7.8 HIGH
CVE-2026-7452 — WRL File Parsing Memory Corruption in Autodesk 3ds Max

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…

3ds_max | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.8 HIGH
CVE-2026-7451 — TIF File Parsing Out-of-Bounds Write in Autodesk 3ds Max

A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data co…

3ds_max | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.5 MEDIUM
CVE-2026-7450 — PAR File Parsing NULL Pointer Dereference in Autodesk 3ds Max

A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a deni…

3ds_max | Memory Corruption
May 26, 2026 Jun 03, 2026
May 26, 2026
Jun 03, 2026
Showing 20 of 6714 Results