Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-73680 — Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands …

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.6 HIGH
CVE-2026-71571 — Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filte…

Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.2 CRITICAL
CVE-2026-67365 — Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11

Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session,…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.0 HIGH
CVE-2026-64887 — Airwall - Hardcoded Secrets

Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.

| Cryptography
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.0 HIGH
CVE-2026-34492 — Airwall - Arbitrary file read

External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
2.9 LOW
CVE-2026-27871 — TL280

Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63.

Remote | Cryptography
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19910 — PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execut…

PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …

| Cryptography
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19909 — PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability

PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX…

| Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.1 HIGH
CVE-2026-19908 — PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected install…

| Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-18554 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

db2_mirror_for_i | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.4 MEDIUM
CVE-2026-18178 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

db2_mirror_for_i | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.4 MEDIUM
CVE-2026-17227 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.

db2_mirror_for_i | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.3 MEDIUM
CVE-2026-17209 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.

db2_mirror_for_i | Remote | Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.9 CRITICAL
CVE-2026-17186 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

db2_mirror_for_i | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-17184 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

db2_mirror_for_i | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-17182 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

db2_mirror_for_i | Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.3 CRITICAL
CVE-2026-17181 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

db2_mirror_for_i | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.5 HIGH
CVE-2026-17179 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.

db2_mirror_for_i | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-17177 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

db2_mirror_for_i | Remote | Denial of Service
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-17175 — IBM Db2 Mirror for i is affected by multiple vulnerabilities

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

db2_mirror_for_i | Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10624 Results