|
161
|
3.1 |
LOW
Network
|
-
|
-
|
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Contain…
Update
|
CWE-601
Open Redirect
|
CVE-2026-7364
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
5.5 |
MEDIUM
Local
|
-
|
-
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of service.
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-7771
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
5.3 |
MEDIUM
Network
|
-
|
-
|
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attack…
Update
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-8861
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
7.1 |
HIGH
Network
|
-
|
-
|
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Update
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-56171
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-57980
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
New
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-16235
|
2026-07-21 02:15 |
2026-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
7.5 |
HIGH
Network
|
-
|
-
|
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the…
New
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-6656
|
2026-07-21 02:15 |
2026-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipul…
New
|
CWE-602
Client-Side Enforcement of Server-Side Security
|
CVE-2026-13724
|
2026-07-21 02:15 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
8.2 |
HIGH
Network
|
-
|
-
|
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable.
Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-der…
New
|
CWE-338 CWE-340
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Generation of Predictable Numbers or Identifiers
|
CVE-2026-13577
|
2026-07-21 02:15 |
2026-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS.
This issue affects Q-smar…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6793
|
2026-07-21 02:15 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|