Common Vulnerabilities and Exposures (CVE)

CVE-2026-17173

Aug 17, 2026 18:06:45 UTC

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.

CVE-2026-50773

Aug 17, 2026 18:06:17 UTC

An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.

CVE-2026-17182

Aug 17, 2026 18:06:03 UTC

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

CVE-2026-18178

Aug 17, 2026 18:04:55 UTC

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

CVE-2026-46345

Aug 17, 2026 18:03:44 UTC

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not...

CVE-2026-50772

Aug 17, 2026 18:03:33 UTC

An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.

CVE-2026-74244

Aug 17, 2026 18:02:45 UTC

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stri...

CVE-2026-50770

Aug 17, 2026 18:00:37 UTC

An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.

CVE-2026-73052

Aug 17, 2026 18:00:16 UTC

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary J...

CVE-2026-16080

Aug 17, 2026 17:59:38 UTC

The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of su...

CVE-2026-50769

Aug 17, 2026 17:58:40 UTC

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true...

CVE-2026-74802

Aug 17, 2026 17:58:26 UTC

SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can...

CVE-2026-16905

Aug 17, 2026 17:58:07 UTC

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.

CVE-2026-17175

Aug 17, 2026 17:57:59 UTC

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

CVE-2026-18554

Aug 17, 2026 17:57:46 UTC

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.