CVE Vulnerability Database

Search and browse 393,396 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13759HIGH8.8IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec...
CVE-2026-13449CRITICAL9.1IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE...
CVE-2026-12086MEDIUM5.5IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug...
CVE-2026-12085MEDIUM6.5IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8....
CVE-2026-12084HIGH7.5IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which...
CVE-2026-11906MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-11806HIGH7.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability...
CVE-2026-11714CRITICAL9.8IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover...
CVE-2026-11712CRITICAL9.3IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-11708CRITICAL9.3IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-11595HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the adm...
CVE-2026-11546CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulner...
CVE-2026-10564HIGH8.2IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss...
CVE-2026-10560CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoi...
CVE-2026-10546MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( ...
CVE-2026-10140CRITICAL9.6IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API client...
CVE-2026-10134CRITICAL10IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and...
CVE-2026-10129HIGH8.5IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th...
CVE-2026-10109CRITICAL9.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth...
CVE-2025-36372MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-58138CRITICAL9.8Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote...
CVE-2026-10513HIGH7.2The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 v...
CVE-2026-9263HIGH8.1The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the l...
CVE-2026-8864HIGH7.3The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel...
CVE-2026-58377HIGH8.6JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to ...