[NEW] [medium] IBM DB2: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in IBM DB2 to carry out a Denial of Service attack and execute arbitrary program code.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
An attacker can exploit multiple vulnerabilities in IBM DB2 to carry out a Denial of Service attack and execute arbitrary program code.
A remote, authenticated attacker can exploit a vulnerability in Grafana to manipulate files.
A remote, anonymous attacker can exploit a vulnerability in FreeRDP to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in IBM Langflow Desktop OSS to gain administrative privileges, execute arbitrary code, bypass security measures, manipulate and disclose data, or cause a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in IBM Semeru, as used in the Power Hardware Management Console and IBM DB2, to execute arbitrary program code.
A remote, anonymous attacker can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.
A local attacker can exploit a vulnerability in HCL BigFix to carry out a denial of service attack.
A remote, authenticated or anonymous attacker can exploit multiple vulnerabilities in Grafana to carry out a denial of service attack, execute code, or disclose information.
An attacker can exploit multiple vulnerabilities in Keycloak to bypass security measures, manipulate data, and disclose confidential information.
A remote, authenticated attacker can exploit a vulnerability in ProFTPD to carry out a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in Ruby and Ruby on Rails to bypass security measures and execute arbitrary code.
An attacker can exploit multiple vulnerabilities in Composer to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Dell PowerProtect Data Domain OS to execute arbitrary code – even with root privileges – to gain elevated rights – including administrative rights – to bypass security measures, manipulate data, disclose confidential information…
A remote, anonymous attacker can exploit a vulnerability in Microsoft Edge to bypass security measures and manipulate or disclose confidential information.
A local attacker can exploit a vulnerability in QT to execute arbitrary program code.
A remote, anonymous attacker can exploit a vulnerability in IBM i to bypass security measures.
A local attacker can exploit a vulnerability in QT to bypass security measures.
An attacker can exploit multiple vulnerabilities in Microsoft Windows Backup Service, Microsoft Windows Admin Center, and Microsoft Windows Remote Desktop Web Client to disclose information and gain elevated privileges.
An attacker can exploit multiple vulnerabilities in Grafana to conduct a denial of service attack or perform cross-site scripting attacks.
A remote, anonymous attacker can exploit a vulnerability in nghttp2 to carry out a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Composer to bypass security mechanisms, write arbitrary files, or disclose information. Certain configurations may be required for successful exploitation.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to execute arbitrary program code with the privileges of the service.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux to cause a denial-of-service attack or potentially execute arbitrary code.
A remote, anonymous attacker can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.
A remote attacker can exploit a vulnerability in Ruby to disclose information.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack or achieve unspecified effects.
A remote, anonymous attacker can exploit multiple vulnerabilities in Adobe Acrobat and Adobe Acrobat Reader to execute arbitrary code, disclose sensitive information, or cause a denial-of-service.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to conduct a Denial of Service attack or potentially execute arbitrary code.
A remote attacker can exploit multiple vulnerabilities in various Drupal extensions to manipulate or disclose data, as well as to conduct cross-site scripting attacks.
An attacker can exploit multiple vulnerabilities in cyrus imap to bypass security measures and disclose or manipulate data.
A remote, authenticated attacker can exploit a vulnerability in IBM Cognos Analytics to manipulate files.
A remote, anonymous attacker can exploit a vulnerability in various HTTP/2 server implementations such as the Apache Traffic Server to conduct a Denial of Service attack.
Multiple vulnerabilities have been discovered in Mattermost Server. They allow an attacker to cause an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause data integrity issues and an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in WordPress. They allow an attacker to cause remote arbitrary code execution, SQL injection (SQLi), and security policy bypass. CERT-FR is aware of a public proof of concept.
On July 17, 2026, WordPress released a patch for two vulnerabilities: CVE-2026-60137: a SQL injection (SQLi); CVE-2026-63030: this allows a security policy bypass. An attacker can exploit these two vulnerabilities, in combination, to gain a...
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in account takeover, cross-site scripting, SSRF bypass, information disclosure or denial of service. https://security-tracker.debian.org/tracker/DSA…
A flaw was discovered in tiff, a Tag Image File Format library, which may result in denial of service or the execution of arbitrary code if malformed image files are processed. https://security-tracker.debian.org/tracker/DSA-6392-1
Two vulnerabilities have been fixed in WordPress Core 6.8.6, 6.9.5, and 7.0.2. An unauthenticated malicious actor can exploit the vulnerabilities remotely to execute arbitrary code. This requires sending a malicious HTTP request to the batch API of a WordPress site. Since vulnera…
Summary A wrong policy can be an open door. You have to check input.attributes.request.http.truncated_body in your policy. Description Incomplete fix for CVE-2026-50197: an oversized declared-Content-Length body still hands OPA an empty parsed_body, so deny-on-presence Rego po…
Description The routesrv component exposes the full cluster route topology (Ingress/RouteGroup configurations, backend URLs, filter chains, OAuth/OIDC callback paths) and cache-cluster topology (Redis/Valkey shard addresses) over plain HTTP with zero authentication. Any pod in t…
Authenticated full-read SSRF in CloudTAK /api/esri* routes — user-controlled URL fetched with no IP-classification guard Summary Every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the p…
Impact The trie language model code introduced in PocketSphinx 5prealpha failed to check various boundary conditions when reading the headers of ARPA, DMP, and binary format language model files. In the case of invalid, corrupted or malicious input files, this could lead to stac…
Summary The HTML specification requires that a MathML <annotation-xml> element with encoding="text/html" or encoding="application/xhtml+xml" is treated as an HTML integration point. Content inside it must be parsed as HTML, not MathML. AngleSharp does not implement this correctl…
<html><head></head><body><h1>Path Traversal in <code>proot-distro copy</code> — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs</h1> <h2>Repository</h2> <p>https://github.com/termux/proot-distro</p> <p><strong>Maintainer:</strong> @sylirre</p> <hr> <…
Summary ExifReader 4.40.0 can throw an uncaught RangeError: Offset is outside the bounds of the DataView while parsing crafted HEIC/AVIF files. The file only needs a valid leading ftyp box with a HEIC/AVIF major brand followed by a malformed ISO-BMFF box, such as an empty 8-byte…
1. Header | Field | Value | |---|---| | Title | Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641) | | Project | Flask-Reuploaded (flask_uploads) | | Affected | <= 1.5.0 (latest release; commit ae31c3f91da40b465c…
Summary The TypeScript Prompty loader used gray-matter without overriding executable frontmatter engines. gray-matter supports JavaScript frontmatter blocks such as ---js and evaluates them while parsing. An attacker-controlled .prompty file could therefore execute arbitrary Java…