| Sep 25 | Ontology comments can break out of generated JSDoc and inject executable TypeScript | pkg:github/google/schema-dts@2.0.0 GHSA-c4f4-pq98-f2p2High8.0fixed in 2.0.1 | | High8.0 | 2.0.1 |
| Sep 25 | Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host GHSA-v234-4jrq-mgg6High8.5fixed in 1.15962.0 | | High8.5 | 1.15962.0 |
| Sep 25 | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1. CVE-2026-10758High7.5no fix yet | | High7.5 | No fix yet |
| Sep 25 | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. CVE-2026-5267High7.5no fix yet | | High7.5 | No fix yet |
| Sep 25 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. CVE-2026-100208High7.5fixed in Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea | | High7.5 | Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea |
| Sep 25 | Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with... CVE-2026-96812High8.8fixed in gVisor 573a9e73cf844f | | High8.8 | gVisor 573a9e73cf844f |
| Sep 25 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. CVE-2026-84862High7.2no fix yet | | High7.2 | No fix yet |
| Sep 25 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. CVE-2026-84882High7.5no fix yet | | High7.5 | No fix yet |
| Sep 25 | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. CVE-2026-93306High7.1no fix yet | | High7.1 | No fix yet |
| Sep 25 | A use-after-free vulnerability was found in QEMU's 9pfs subsystem. CVE-2026-93834High8.8no fix yet | | High8.8 | No fix yet |
| Sep 25 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a... CVE-2026-85029High7.5no fix yet | | High7.5 | No fix yet |
| Sep 25 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. CVE-2026-85542High8.8no fix yet | | High8.8 | No fix yet |
| Sep 25 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. CVE-2026-84884High7.5no fix yet | | High7.5 | No fix yet |
| Sep 25 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. CVE-2026-84893High7.6no fix yet | | High7.6 | No fix yet |
| Sep 25 | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. CVE-2026-97875High8.1fixed in rojo 7.7.0 | | High8.1 | rojo 7.7.0 |
| Sep 24 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. CVE-2026-82164High7.1fixed in Trusted Device Client, 8.1.359.0 | | High7.1 | Trusted Device Client, 8.1.359.0 |
| Sep 24 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable... CVE-2026-89325High7.8no fix yet | | High7.8 | No fix yet |
| Sep 24 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. CVE-2026-86857High8.4fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 | | High8.4 | ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 |
| Sep 24 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. CVE-2026-86858High8.7fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 | | High8.7 | ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 |
| Sep 24 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. CVE-2026-86859High8.7fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 | | High8.7 | ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 |
| Sep 24 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. CVE-2026-81455High8.6fixed in ThinOS 10 SecurityAddon_2605.10.2766_T10 | | High8.6 | ThinOS 10 SecurityAddon_2605.10.2766_T10 |
| Sep 24 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. CVE-2026-81473High8.1fixed in Rugged Control Center (RCC) 5.2.206 | | High8.1 | Rugged Control Center (RCC) 5.2.206 |
| Sep 24 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. CVE-2026-82157High8.3fixed in ThinOS 10 SecurityAddon_2605.10.2766_T10 | | High8.3 | ThinOS 10 SecurityAddon_2605.10.2766_T10 |
| Sep 24 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer... CVE-2026-13248High8.8fixed in PD45 Industrial Printer F10.22.030745 | | High8.8 | PD45 Industrial Printer F10.22.030745 |
| Sep 24 | PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding CVE-2026-96749High7.5fixed in 4.18.2 | | High7.5 | 4.18.2 |
| Sep 24 | PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters CVE-2026-96748High8.3fixed in 4.18.2 | | High8.3 | 4.18.2 |
| Sep 24 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. CVE-2026-95985High8.6fixed in Kiro IDE 1.0.242 | | High8.6 | Kiro IDE 1.0.242 |
| Sep 24 | Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as... CVE-2026-96744High7.1fixed in Laravel MongoDB (PHP) 5.11.0 | | High7.1 | Laravel MongoDB (PHP) 5.11.0 |
| Sep 24 | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. CVE-2026-96750High7.3fixed in Compass 1.49.12 | | High7.3 | Compass 1.49.12 |
| Sep 24 | Heap buffer overflow via mid-scan command list growth in client topology monitoring CVE-2026-96746High8.3fixed in 1.30.12, 2.5.5 | | High8.3 | 1.30.12, 2.5.5 |
| Sep 24 | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to... CVE-2026-90959High8.1no fix yet | | High8.1 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. CVE-2026-81552High8.8no fix yet | | High8.8 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. CVE-2026-82093High8.8no fix yet | | High8.8 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory. CVE-2026-82094High7.1no fix yet | | High7.1 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. CVE-2026-81539High8.8no fix yet | | High8.8 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVE-2026-81545High8.8no fix yet | | High8.8 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. CVE-2026-81547High8.8no fix yet | | High8.8 | No fix yet |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVE-2026-81548High8.8no fix yet | | High8.8 | No fix yet |
| Sep 24 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. CVE-2026-77874High8.6no fix yet | | High8.6 | No fix yet |
| Sep 24 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. CVE-2026-12559High7.3no fix yet | | High7.3 | No fix yet |
| Sep 24 | A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code... CVE-2026-95519High7.8no fix yet | | High7.8 | No fix yet |
| Sep 24 | A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell... CVE-2026-95521High7.8no fix yet | | High7.8 | No fix yet |
| Sep 24 | Dell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass GHSA-wcfm-jp7m-rffhHighfixed in RefertoAdvisory | | High | RefertoAdvisory |
| Sep 24 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. CVE-2026-78309High8.8fixed in DIAEnergie 1.11.00.022 | | High8.8 | DIAEnergie 1.11.00.022 |
| Sep 24 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. CVE-2026-78311High8.8fixed in DIAEnergie 1.11.00.022 | | High8.8 | DIAEnergie 1.11.00.022 |
| Sep 24 | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. CVE-2026-97185High7.8no fix yet | | High7.8 | No fix yet |
| Sep 24 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4. CVE-2026-92470High7.7fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 | | High7.7 | GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 |
| Sep 23 | Microsoft Office Outlook Remote Code Execution Vulnerability CVE-2026-70125High8.8fixed in Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea | | High8.8 | Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea |
| Sep 23 | A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource. CVE-2026-75887High7.5no fix yet | | High7.5 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts. CVE-2026-80423High8.8no fix yet | | High8.8 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. CVE-2026-81208High7.7no fix yet | | High7.7 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. CVE-2026-81536High7.7no fix yet | | High7.7 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection. CVE-2026-81537High8.8no fix yet | | High8.8 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation. CVE-2026-80412High8.8no fix yet | | High8.8 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVE-2026-80425High8.8no fix yet | | High8.8 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. CVE-2026-6794High7.8no fix yet | | High7.8 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. CVE-2026-6935High7.8no fix yet | | High7.8 | No fix yet |
| Sep 23 | A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the... CVE-2026-75886High7.2no fix yet | | High7.2 | No fix yet |
| Sep 23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVE-2026-80379High8.8no fix yet | | High8.8 | No fix yet |
| Sep 23 | gh-aw: HTTPS egress allowlist bypass via TLS SNI domain fronting GHSA-x78f-wrrj-4h24High8.3fixed in 0.89.17 | | High8.3 | 0.89.17 |