|
561
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot d…
New
|
CWE-22
Path Traversal
|
CVE-2026-4502
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
7.5 |
HIGH
Network
|
-
|
-
|
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4503
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
5.3 |
MEDIUM
Adjacent
|
-
|
-
|
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.
New
|
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints
|
CVE-2025-36180
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.
New
|
CWE-256
Plaintext Storage of a Password
|
CVE-2025-36335
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
6.4 |
MEDIUM
Network
|
-
|
-
|
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. A malicious actor could cause user-controlled code to ru…
New
|
CWE-284
Improper Access Control
|
CVE-2026-2311
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../)…
New
|
CWE-22
Path Traversal
|
CVE-2026-3345
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
8.8 |
HIGH
Local
|
-
|
-
|
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An a…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-6389
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
8.8 |
HIGH
Network
|
-
|
-
|
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment varia…
New
|
CWE-94
Code Injection
|
CVE-2026-6543
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
7.8 |
HIGH
Local
|
-
|
-
|
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-5403
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
4.7 |
MEDIUM
Local
|
-
|
-
|
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-5404
|
2026-05-2 00:27 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|