CVE ID :CVE-2026-16174 Published : Sept. 10, 2026, 11:16 p.m. | 1 hour, 43 minutes ago Description :Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful…
CVE-2026-87958 – IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions
CVE ID :CVE-2026-87958 Published : Sept. 10, 2026, 10:17 p.m. | 2 hours, 43 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where…
CVE-2026-84889 – A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem
CVE ID :CVE-2026-84889 Published : Sept. 10, 2026, 10:17 p.m. | 2 hours, 43 minutes ago Description :IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due…
CVE-2026-82107 – DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
CVE ID :CVE-2026-82107 Published : Sept. 10, 2026, 10:17 p.m. | 2 hours, 43 minutes ago Description :IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive…
CVE-2026-82100 – DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
CVE ID :CVE-2026-82100 Published : Sept. 10, 2026, 10:17 p.m. | 2 hours, 43 minutes ago Description :IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a…
CVE-2026-87931 – Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow
CVE ID :CVE-2026-87931 Published : Sept. 10, 2026, 12:17 a.m. | 42 minutes ago Description :A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is…
CVE-2026-88069 – Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis
CVE ID :CVE-2026-88069 Published : Sept. 9, 2026, 10:18 p.m. | 2 hours, 41 minutes ago Description :Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive…
CVE-2026-87995 – Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
CVE ID :CVE-2026-87995 Published : Sept. 9, 2026, 10:18 p.m. | 2 hours, 41 minutes ago Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered…
CVE-2026-87016 – Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
CVE ID :CVE-2026-87016 Published : Sept. 9, 2026, 10:18 p.m. | 2 hours, 41 minutes ago Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and…
CVE-2026-87911 – Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
CVE ID :CVE-2026-87911 Published : Sept. 9, 2026, 8:21 p.m. | 4 hours, 39 minutes ago Description :An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs…