6.5

CVSS3.1

CVE-2025-36122 - IBMยฎ Db2ยฎ is vulnerable to a denial of service with a specially crafted query when stmtheap is set โ€ฆ

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.

๐Ÿ“… Published: April 30, 2026, 9:48 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 9:48 p.m.

5.3

CVSS3.1

CVE-2025-14688 - IBMยฎ Db2ยฎ is vulnerable to a denial of service when fetching from certain tables under specific conโ€ฆ

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.

๐Ÿ“… Published: April 30, 2026, 9:48 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 9:48 p.m.

8.7

CVSS4.0

CVE-2026-7503 - code-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow

A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow. The attack can be lauโ€ฆ

๐Ÿ“… Published: April 30, 2026, 9:45 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 4:56 p.m.

6.4

CVSS3.1

CVE-2026-2311 - IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. ย A malicious actor could cause user-controlled code to run with administrator privilege.

๐Ÿ“… Published: April 30, 2026, 9:45 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 9:45 p.m.

8.7

CVSS4.0

CVE-2026-7551 - HKUDS OpenHarness Remote Command Execution via /bridge Slash Command

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Attackers can invoke the /bridge spawn command with attacker-controlled command text that is forwarded tโ€ฆ

๐Ÿ“… Published: April 30, 2026, 9:29 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 6:22 p.m.

5.3

CVSS3.1

CVE-2025-36180 - Inadequate Pod Communication Restrictions, affects watsonx.data

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

๐Ÿ“… Published: April 30, 2026, 9:28 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 9:28 p.m.

8.8

CVSS3.1

CVE-2026-6389 - IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected โ€ฆ

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive clusterโ€‘wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, eโ€ฆ

๐Ÿ“… Published: April 30, 2026, 9:17 p.m. ๐Ÿ”„ Last Modified: May 5, 2026, 12:17 a.m.

6.5

CVSS3.1

CVE-2026-6542 - Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

๐Ÿ“… Published: April 30, 2026, 9:16 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 6:21 p.m.

5.3

CVSS4.0

CVE-2026-7502 - LinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization

A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotโ€ฆ

๐Ÿ“… Published: April 30, 2026, 9:15 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 9:15 p.m.

6.2

CVSS3.1

CVE-2025-36335 - Vulnerabilities found

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.

๐Ÿ“… Published: April 30, 2026, 9:12 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 9:12 p.m.
Total resulsts: 348147
Page 79 of 34,815
ยซ previous page ยป next page
Filters