🚨 CVE-2026-17443
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
🚨 CVE-2026-17444
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
🚨 CVE-2026-17469
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [CVE-2026-17470, CVE-2026-17469]
IBM i is vulnerable to denial of service due to a buffer overflow and off-by-one write [CVE-2026-17470, CVE-2026-17469] in Line Printer Daemon (LPD) as described in the vulnerability details section.
🚨 CVE-2026-17470
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [CVE-2026-17470, CVE-2026-17469]
IBM i is vulnerable to denial of service due to a buffer overflow and off-by-one write [CVE-2026-17470, CVE-2026-17469] in Line Printer Daemon (LPD) as described in the vulnerability details section.
🚨 CVE-2026-17483
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
🎖@cveNotify
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
🎖@cveNotify
Ibm
Security Bulletin: IBM Db2 Mirror for i is affected by multiple vulnerabilities [CVE-2026-18567, CVE-2026-16660, CVE-2026-17483]
IBM Db2 Mirror for i is affected by multiple vulnerabilities as described in the vulnerability details section.
🚨 CVE-2026-17499
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-17621
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
🎖@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge…
Langflow uses filesystem path construction as part of several components and API endpoints, including the Directory component, the Knowledge Base connector ingestion endpoint, and the Knowledge Base flow component. In the Directory component, user-supplied…
🚨 CVE-2026-17622
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
🎖@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge…
Langflow uses filesystem path construction as part of several components and API endpoints, including the Directory component, the Knowledge Base connector ingestion endpoint, and the Knowledge Base flow component. In the Directory component, user-supplied…
🚨 CVE-2026-17627
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
🎖@cveNotify
Ibm
Security Bulletin: Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint
Langflow provides a voice-mode feature through a WebSocket API endpoint that accepts a flow identifier as a URL path parameter and uses it to retrieve the target flow description and persist conversation messages against that flow. The endpoint authenticates…
🚨 CVE-2026-17631
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
🎖@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components
Langflow uses outbound HTTP request functionality as part of several flow components, including components for LM Studio, Home Assistant, DeepSeek, xAI, Glean, HuggingFace Inference API, Ollama, LiteLLM, and Docling Serve. These components accept user-supplied…
🚨 CVE-2026-18073
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-18076
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-18078
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerability in Save Restore [CVE-2026-18078]
IBM i is vulnerable to denial of service due to an integer overflow [CVE-2026-18078] in Save Restore as described in the vulnerability details section.
🚨 CVE-2026-18175
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [CVE-2026-18175…
IBM i is vulnerable to manipulation of database transactions due to improper authorization [CVE-2026-18175] and allowing unathorized access due to improper validation [CVE-2026-18221] in Distributed Data Management (DDM) / Distributed Relational Database…
🚨 CVE-2026-18221
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [CVE-2026-18175…
IBM i is vulnerable to manipulation of database transactions due to improper authorization [CVE-2026-18175] and allowing unathorized access due to improper validation [CVE-2026-18221] in Distributed Data Management (DDM) / Distributed Relational Database…
🚨 CVE-2026-18341
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Buffer Overflow Vulnerability [CVE-2026-18341]
IBM i is vulnerable to a buffer overflow due to an integer underflow [CVE-2026-18341] as described in the vulnerability details section.
🚨 CVE-2026-18486
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
🎖@cveNotify
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
🎖@cveNotify
Ibm
Security Bulletin: IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution
IBM ContextForge MCP Gateway allows authenticated users with developer privileges to supply a jq program in the tool jsonpath_filter field that executes unrestricted built-in such as `$ENV` inside the server process, exposing environment variables including…
🚨 CVE-2026-18489
IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
🎖@cveNotify
IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
🎖@cveNotify
Ibm
Security Bulletin: IBM ContextForge Translate is affected by cross-client credential context confusion
IBM ContextForge Translate utility contains a credential context confusion vulnerability in the Translate service (`mcpgateway/translate.py`) when the `--enable-dynamic-env` opt-in flag is active. The Translate service is a standalone component within the…
🚨 CVE-2026-38961
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
🎖@cveNotify
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
🎖@cveNotify
🚨 CVE-2026-75430
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
🎖@cveNotify
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
🎖@cveNotify
Gist
CVE-2026-75430 - PowerJob Worker /worker/deployContainer Unauthenticated Remote Code Execution
CVE-2026-75430 - PowerJob Worker /worker/deployContainer Unauthenticated Remote Code Execution - CVE-2026-75430.md
🚨 CVE-2026-78745
An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)
🎖@cveNotify
An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)
🎖@cveNotify
GitHub
n0c71v3x/CVE-2026-78745
Contribute to n0c71v3x/CVE-2026-78745 development by creating an account on GitHub.