A vulnerability classified as critical was found in IBM WebSphere Extreme Scale up to 8.6.1.6. This issue affects the function ORB.string_to_object of the file ogclient.jar. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-13773. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in IBM WebSphere Extreme Scale up to 8.6.1.6. Impacted is the function Class.forName of the component Query Language Handler. Performing a manipulation results in use of externally-controlled input to select classes or code.
This vulnerability is reported as CVE-2026-13772. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability has been found in IBM Langflow OSS up to 1.9.6 and classified as critical. The impacted element is an unknown function of the component Streamable MCP Transport Endpoint. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-7663. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in IBM App Connect Enterprise and Integration Bus for zOS. It has been classified as critical. This impacts an unknown function of the component File Handler. This manipulation causes sql injection.
This vulnerability is handled as CVE-2026-3602. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability identified as problematic has been detected in IBM InfoSphere Information Server up to 11.7.1.6. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-9836. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in IBM WebSphere Application Server 8.5/9.0. This issue affects some unknown processing. The manipulation results in http request smuggling.
This vulnerability is known as CVE-2026-11541. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in IBM WebSphere Application Server 8.5/9.0. It has been classified as problematic. This issue affects some unknown processing of the component Administrative Console. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-11594. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability labeled as critical has been found in DokuWiki 2025-05-14b. This impacts the function register of the file inc/auth.php of the component Librarian. Executing a manipulation can lead to weak password recovery.
This vulnerability is handled as CVE-2026-37106. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as problematic was found in GitHub Enterprise Server up to 3.17.16/3.18.10/3.19.7/3.20.3. This vulnerability affects unknown code of the component REST API. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-10585. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in GitHub Enterprise Server up to 3.17.16/3.18.10/3.19.7/3.20.3. This impacts an unknown function. This manipulation causes missing authorization.
The identification of this vulnerability is CVE-2026-9132. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in GitHub Enterprise Server up to 3.17.16/3.18.10/3.19.7/3.20.3/3.21.1. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in clickjacking.
This vulnerability is cataloged as CVE-2026-9106. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in w1.fi hostapd up to 2.11. It has been declared as critical. The affected element is the function hostapd_process_ml_assoc_req. Executing a manipulation of the argument links[] can lead to off-by-one.
This vulnerability is tracked as CVE-2026-58374. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in IBM WebSphere Extreme Scale up to 8.6.1.6. This vulnerability affects unknown code of the component Session Attribute Handler. This manipulation causes deserialization.
This vulnerability is registered as CVE-2026-13759. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in IBM Db2 up to 11.5.9/12.1.4. This vulnerability affects unknown code. The manipulation results in file and directory information exposure.
This vulnerability is identified as CVE-2025-36372. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in IBM WebSphere Application Server 8.5/9.0. This issue affects some unknown processing of the component Administrative Console. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-11595. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.