Skip to content

High advisories

6,838 high severity advisories, newest first

60 of 6,838 advisories

DateAdvisory
Sep 25Ontology comments can break out of generated JSDoc and inject executable TypeScript | pkg:github/google/schema-dts@2.0.0
GHSA-c4f4-pq98-f2p2High8.0fixed in 2.0.1
Sep 25Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host
GHSA-v234-4jrq-mgg6High8.5fixed in 1.15962.0
Sep 25Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.
CVE-2026-10758High7.5no fix yet
Sep 25Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication.
CVE-2026-5267High7.5no fix yet
Sep 25Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-100208High7.5fixed in Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea
Sep 25Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with...
CVE-2026-96812High8.8fixed in gVisor 573a9e73cf844f
Sep 25IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store.
CVE-2026-84862High7.2no fix yet
Sep 25IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component.
CVE-2026-84882High7.5no fix yet
Sep 25IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface.
CVE-2026-93306High7.1no fix yet
Sep 25A use-after-free vulnerability was found in QEMU's 9pfs subsystem.
CVE-2026-93834High8.8no fix yet
Sep 25IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a...
CVE-2026-85029High7.5no fix yet
Sep 25IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality.
CVE-2026-85542High8.8no fix yet
Sep 25IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format.
CVE-2026-84884High7.5no fix yet
Sep 25IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service.
CVE-2026-84893High7.6no fix yet
Sep 25Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding.
CVE-2026-97875High8.1fixed in rojo 7.7.0
Sep 24Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability.
CVE-2026-82164High7.1fixed in Trusted Device Client, 8.1.359.0
Sep 24An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable...
CVE-2026-89325High7.8no fix yet
Sep 24ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform.
CVE-2026-86857High8.4fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32
Sep 24ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform.
CVE-2026-86858High8.7fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32
Sep 24ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform.
CVE-2026-86859High8.7fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32
Sep 24Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability.
CVE-2026-81455High8.6fixed in ThinOS 10 SecurityAddon_2605.10.2766_T10
Sep 24Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability.
CVE-2026-81473High8.1fixed in Rugged Control Center (RCC) 5.2.206
Sep 24Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability.
CVE-2026-82157High8.3fixed in ThinOS 10 SecurityAddon_2605.10.2766_T10
Sep 24An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer...
CVE-2026-13248High8.8fixed in PD45 Industrial Printer F10.22.030745
Sep 24PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
CVE-2026-96749High7.5fixed in 4.18.2
Sep 24PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
CVE-2026-96748High8.3fixed in 4.18.2
Sep 24The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context.
CVE-2026-95985High8.6fixed in Kiro IDE 1.0.242
Sep 24Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as...
CVE-2026-96744High7.1fixed in Laravel MongoDB (PHP) 5.11.0
Sep 24MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view.
CVE-2026-96750High7.3fixed in Compass 1.49.12
Sep 24Heap buffer overflow via mid-scan command list growth in client topology monitoring
CVE-2026-96746High8.3fixed in 1.30.12, 2.5.5
Sep 24A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to...
CVE-2026-90959High8.1no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.
CVE-2026-81552High8.8no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
CVE-2026-82093High8.8no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
CVE-2026-82094High7.1no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
CVE-2026-81539High8.8no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-81545High8.8no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.
CVE-2026-81547High8.8no fix yet
Sep 24IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-81548High8.8no fix yet
Sep 24IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection.
CVE-2026-77874High8.6no fix yet
Sep 24A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application.
CVE-2026-12559High7.3no fix yet
Sep 24A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code...
CVE-2026-95519High7.8no fix yet
Sep 24A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell...
CVE-2026-95521High7.8no fix yet
Sep 24Dell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass
GHSA-wcfm-jp7m-rffhHighfixed in RefertoAdvisory
Sep 24SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78309High8.8fixed in DIAEnergie 1.11.00.022
Sep 24SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78311High8.8fixed in DIAEnergie 1.11.00.022
Sep 24A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays.
CVE-2026-97185High7.8no fix yet
Sep 24GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.
CVE-2026-92470High7.7fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1
Sep 23Microsoft Office Outlook Remote Code Execution Vulnerability
CVE-2026-70125High8.8fixed in Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea
Sep 23A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.
CVE-2026-75887High7.5no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.
CVE-2026-80423High8.8no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials.
CVE-2026-81208High7.7no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
CVE-2026-81536High7.7no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.
CVE-2026-81537High8.8no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.
CVE-2026-80412High8.8no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-80425High8.8no fix yet
Sep 23IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management.
CVE-2026-6794High7.8no fix yet
Sep 23IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution.
CVE-2026-6935High7.8no fix yet
Sep 23A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the...
CVE-2026-75886High7.2no fix yet
Sep 23IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-80379High8.8no fix yet
Sep 23gh-aw: HTTPS egress allowlist bypass via TLS SNI domain fronting
GHSA-x78f-wrrj-4h24High8.3fixed in 0.89.17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.