CVE-2026-82370 |
Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-89078 |
Double Free in GitLab |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-92470 |
Missing Authorization in GitLab |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-93577 |
Integer Overflow or Wraparound in GitLab |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-70125 |
Microsoft Outlook Remote Code Execution Vulnerability |
high |
cve |
0 |
0 |
|
|
|
TF-1931083 |
Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 134.122.200.153:8151 |
high |
Unknown malware |
3 |
0 |
|
|
|
CVE-2026-81537 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-81536 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-81208 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-93352 |
Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-80423 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-75887 |
Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler |
high |
cve |
0 |
0 |
|
|
|
TF-1931073 |
Remcos: ip:port combination that is used for botnet Command&control (C&C) 185.215.151.9:2404 |
high |
Remcos |
2 |
0 |
|
|
|
CVE-2026-80425 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-80412 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-80379 |
DataStage on Cloud Pak for Data has several vulnerabilities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-6935 |
Multiple Vulnerabilities in IBM Concert Software |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-6928 |
Multiple Vulnerabilities in IBM Concert Software |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-6794 |
Multiple Vulnerabilities in IBM Concert Software |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-75886 |
Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-67231 |
RabbitMQ: Trust-store whitelist by Issuer+Serial only |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-6730 |
Multiple Vulnerabilities in IBM Concert Software |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-6721 |
Multiple Vulnerabilities in IBM Concert Software |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-82369 |
Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-67232 |
RabbitMQ: Web-MQTT decompression bomb |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-67235 |
RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-67404 |
RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-66077 |
RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-66079 |
RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-66070 |
RabbitMQ: CORS * reflects Origin with Allow-Credentials |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-67238 |
RabbitMQ: Atom-table exhaustion via reply-to queue name decoding |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-87899 |
CVE-2026-87899 |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-68492 |
CVE-2026-68492 |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-68490 |
CVE-2026-68490 |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-87900 |
CVE-2026-87900 |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-87898 |
CVE-2026-87898 |
critical |
cve |
0 |
0 |
|
|
|
TF-1931048 |
Tsundere: ip:port combination that is used for botnet Command&control (C&C) 2.26.29.7:443 |
high |
Tsundere |
2 |
0 |
|
|
|
CVE-2026-96889 |
Librsvg: use-after-free when xml includes have duplicated entities |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-85475 |
Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote code execution in the control-plane rsyslog component |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-84719 |
Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-84714 |
Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-84706 |
Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-75884 |
Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-96826 |
WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-82405 |
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-82409 |
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-82407 |
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-86065 |
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-86064 |
Klever-Go: /log controls global node logging |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-82406 |
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace |
high |
cve |
0 |
0 |
|
|
|