| Jul 31 | NLTK: server-side request forgery NLTKHigh8.6Jul 31 | NLTK | High8.6 | 3.10.0 |
| Jul 31 | Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex NLTKHigh7.5Jul 31 | NLTK | High7.5 | 3.10.0 |
| Jul 31 | NLTK: arbitrary file read NLTKHigh7.5Jul 31 | NLTK | High7.5 | 3.10.0 |
| Jul 31 | NLTK: path traversal NLTKHigh7.5Jul 31 | NLTK | High7.5 | 3.10.0 |
| Jul 31 | Adobe Premiere: out-of-bounds write PremiereHigh7.8Jul 31 | Premiere | High7.8 | No fix yet |
| Jul 31 | Red Hat Ansible Automation Platform 2: improper certificate validation Red Hat Ansible Automation Platform 2High8.2Jul 31 | Red Hat Ansible Automation Platform 2 | High8.2 | No fix yet |
| Jul 31 | Red Hat gnome-remote-desktop as shipped: resource exhaustion gnome-remote-desktop as shippedHigh7.5Jul 31 | gnome-remote-desktop as shipped | High7.5 | No fix yet |
| Jul 31 | Incorrect authorization in Strands Agents Tools http_request tool AWSUnratedJul 31 | AWS | Unrated | No fix yet |
| Jul 31 | Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft AWSUnratedJul 31 | AWS | Unrated | No fix yet |
| Jul 31 | A flaw was found in 389 Directory Server 389 Directory ServerHigh7.5Jul 31 | 389 Directory Server | High7.5 | No fix yet |
| Jul 31 | Red Hat: buffer overflow Red HatHigh7.5Jul 31 | Red Hat | High7.5 | No fix yet |
| Jul 31 | Red Hat Advanced Cluster Security 4: insufficient authenticity check Red Hat Advanced Cluster Security 4High8.5Jul 31 | Red Hat Advanced Cluster Security 4 | High8.5 | No fix yet |
| Jul 31 | Red Hat SAML protocol implementation of Keycloak: improper input validation SAML protocol implementation of KeycloakLow3.4Jul 31 | SAML protocol implementation of Keycloak | Low3.4 | No fix yet |
| Jul 31 | Red Hat TokenManager: missing authorization TokenManagerMedium4.2Jul 31 | TokenManager | Medium4.2 | No fix yet |
| Jul 31 | Red Hat group policy evaluation logic of Keycloak: improper authorization group policy evaluation logic of KeycloakMedium6.5Jul 31 | group policy evaluation logic of Keycloak | Medium6.5 | No fix yet |
| Jul 31 | Red Hat keycloak-services: improper input validation keycloak-servicesLow3.7Jul 31 | keycloak-services | Low3.7 | No fix yet |
| Jul 31 | Red Hat Build of Keycloak: information disclosure Red Hat Build of KeycloakMedium6.5Jul 31 | Red Hat Build of Keycloak | Medium6.5 | No fix yet |
| Jul 31 | Red Hat keycloak-services: session fixation keycloak-servicesLow3.4Jul 31 | keycloak-services | Low3.4 | No fix yet |
| Jul 31 | Red Hat Build of: attacker could intercept sensitive authentication codes Red Hat Build of KeycloakMedium4.2Jul 31 | Red Hat Build of Keycloak | Medium4.2 | No fix yet |
| Jul 31 | Red Hat Data Grid 8: missing authorization Red Hat Data Grid 8Medium6.8Jul 31 | Red Hat Data Grid 8 | Medium6.8 | No fix yet |
| Jul 31 | Red Hat Data Grid 8: improper authentication Red Hat Data Grid 8Medium6.8Jul 31 | Red Hat Data Grid 8 | Medium6.8 | No fix yet |
| Jul 31 | Red Hat RoleContainerResource: insecure direct object reference RoleContainerResourceMedium4.9Jul 31 | RoleContainerResource | Medium4.9 | No fix yet |
| Jul 31 | Red Hat yggdrasil-worker-package-manager: argument injection yggdrasil-worker-package-managerHigh7.8Jul 31 | yggdrasil-worker-package-manager | High7.8 | 0.1.4+1 more |
| Jul 31 | Google mcp-toolbox: authentication bypass mcp-toolboxHigh8.0Jul 31 | mcp-toolbox | High8.0 | No fix yet |
| Jul 31 | Google mcp-toolbox: server-side request forgery mcp-toolboxHigh8.0Jul 31 | mcp-toolbox | High8.0 | No fix yet |
| Jul 31 | Google mcp-toolbox: improper authorization mcp-toolboxMedium5.7Jul 31 | mcp-toolbox | Medium5.7 | No fix yet |
| Jul 31 | Google mcp-toolbox: denial of service mcp-toolboxMedium6.6Jul 31 | mcp-toolbox | Medium6.6 | No fix yet |
| Jul 31 | Google mcp-toolbox: improper authorization mcp-toolboxHigh8.1Jul 31 | mcp-toolbox | High8.1 | No fix yet |
| Jul 30 | ansible-collection-redhat-leapp: information disclosure ansible-collection-redhat-leappMedium6.2Jul 30 | ansible-collection-redhat-leapp | Medium6.2 | No fix yet |
| Jul 30 | ansible-collection-redhat-leapp.: insecure permissions ansible-collection-redhat-leapp.Medium5.5Jul 30 | ansible-collection-redhat-leapp. | Medium5.5 | No fix yet |
| Jul 30 | Microsoft Azure Cosmos DB: improper access control Azure Cosmos DBCritical10.0Jul 30 | Azure Cosmos DB | Critical10.0 | No fix yet |
| Jul 30 | IBM WebSphere Application Server: remote code execution WebSphere Application ServerHigh8.5Jul 30 | WebSphere Application Server | High8.5 | No fix yet |
| Jul 30 | IBM Langflow OSS: code injection Langflow OSSCritical9.9Jul 30 | Langflow OSS | Critical9.9 | No fix yet |
| Jul 30 | UCD - IBM: information disclosure UCD - IBMMedium4.3Jul 30 | UCD - IBM | Medium4.3 | No fix yet |
| Jul 30 | IBM Langflow OSS: improper input validation Langflow OSSCritical9.9Jul 30 | Langflow OSS | Critical9.9 | No fix yet |
| Jul 30 | IBM Langflow OSS: attacker could access another user's private vector Langflow OSSHigh8.1Jul 30 | Langflow OSS | High8.1 | No fix yet |
| Jul 30 | IBM Langflow OSS: path traversal Langflow OSSHigh7.5Jul 30 | Langflow OSS | High7.5 | No fix yet |
| Jul 30 | IBM HMC: remote code execution HMCCritical9.8Jul 30 | HMC | Critical9.8 | No fix yet |
| Jul 30 | IBM Security Verify Access: information disclosure Security Verify AccessMedium5.3Jul 30 | Security Verify Access | Medium5.3 | No fix yet |
| Jul 30 | IBM webMethods Integration (on prem): remote code execution webMethods Integration (on prem)Critical9.8Jul 30 | webMethods Integration (on prem) | Critical9.8 | No fix yet |
| Jul 30 | IBM DataPower Gateway: denial of service DataPower GatewayHigh7.5Jul 30 | DataPower Gateway | High7.5 | No fix yet |
| Jul 30 | IBM Langflow OSS: improper access control Langflow OSSMedium6.5Jul 30 | Langflow OSS | Medium6.5 | No fix yet |
| Jul 30 | IBM Db2: buffer overflow Db2High8.4Jul 30 | Db2 | High8.4 | No fix yet |
| Jul 30 | IBM Planning Analytics Local: open redirect Planning Analytics LocalHigh7.5Jul 30 | Planning Analytics Local | High7.5 | No fix yet |
| Jul 30 | IBM Db2: denial of service Db2Medium6.2Jul 30 | Db2 | Medium6.2 | No fix yet |
| Jul 30 | IBM DataPower Gateway: XML external entity DataPower GatewayMedium5.5Jul 30 | DataPower Gateway | Medium5.5 | No fix yet |
| Jul 30 | IBM Operations Analytics - Log Analysis: insufficient session expiration Operations Analytics - Log AnalysisMedium6.3Jul 30 | Operations Analytics - Log Analysis | Medium6.3 | No fix yet |
| Jul 30 | IBM Engineering Requirements Management: cross-site scripting Engineering Requirements Management DOORS and DOORS Web AcceMedium6.1Jul 30 CVE-2025-0152·Engineering Requirements Management DOORS and DOORS Web Acce·No fix yet | Engineering Requirements Management DOORS and DOORS Web Acce | Medium6.1 | No fix yet |
| Jul 30 | IBM Engineering Requirements Management: denial of service Engineering Requirements Management DOORS and DOORS Web AcceHigh7.5Jul 30 CVE-2024-25039·Engineering Requirements Management DOORS and DOORS Web Acce·No fix yet | Engineering Requirements Management DOORS and DOORS Web Acce | High7.5 | No fix yet |
| Jul 30 | IBM WebSphere Application Server: denial of service WebSphere Application ServerHigh7.5Jul 30 | WebSphere Application Server | High7.5 | No fix yet |
| Jul 30 | IBM Langflow OSS: remote code execution Langflow OSSCritical9.8Jul 30 | Langflow OSS | Critical9.8 | No fix yet |
| Jul 30 | IBM Langflow OSS: improper access control Langflow OSSHigh7.1Jul 30 | Langflow OSS | High7.1 | No fix yet |
| Jul 30 | IBM PowerVM Hypervisor: buffer overflow PowerVM HypervisorHigh8.4Jul 30 | PowerVM Hypervisor | High8.4 | No fix yet |
| Jul 30 | Red Hat Samba: out-of-bounds read SambaMedium5.3Jul 30 | Samba | Medium5.3 | No fix yet |
| Jul 30 | Red Hat Enterprise Linux 10: improper authorization Red Hat Enterprise Linux 10High8.8Jul 30 | Red Hat Enterprise Linux 10 | High8.8 | No fix yet |
| Jul 30 | SolarWinds Web Help Desk: authentication bypass Web Help DeskCritical9.8Jul 30 | Web Help Desk | Critical9.8 | No fix yet |
| Jul 30 | IBM WebSphere Application Server: remote attacker could bypass security... WebSphere Application ServerHigh7.5Jul 30 | WebSphere Application Server | High7.5 | No fix yet |
| Jul 30 | IBM WebSphere Application Server - Liberty: cross-site request forgery WebSphere Application Server - LibertyHigh8.3Jul 30 | WebSphere Application Server - Liberty | High8.3 | No fix yet |
| Jul 30 | IBM App Connect Enterprise: path traversal App Connect EnterpriseCritical9.8Jul 30 | App Connect Enterprise | Critical9.8 | No fix yet |
| Jul 30 | IBM Enterprise Build of Quarkus: denial of service Enterprise Build of QuarkusHigh7.5Jul 30 | Enterprise Build of Quarkus | High7.5 | No fix yet |