Where
-Infinity
0

IBM API Connect V12 OnPrem29 vulnerabilities

First published (updated )
Advisory
IBM-7278909

IBM API Connect Default Credentials

Risk 86
Severity
9.8
First published (updated )

Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)

Risk 76
Severity
7.5
First published (updated )

Apache CXF: XXE vulnerability in WS-Transfer functionality

Risk 29
Severity
5.3
First published (updated )

Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository

Risk 92
Severity
9.8
First published (updated )

Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

Risk 82
Severity
8.7
First published (updated )

opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

Risk 43
Severity
7.5
First published (updated )

opentelemetry-js: Prometheus exporter process crash via malformed HTTP request

Risk 43
Severity
7.5
First published (updated )

i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite

Risk 54
Severity
8.2
First published (updated )

Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)

Risk 66
Severity
9.1
First published (updated )

Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

Risk 43
Severity
2.9
First published (updated )

Netty: epoll transport denial of service via RST on half-closed TCP connection

Risk 43
Severity
7.5
First published (updated )

GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

Risk 69
Severity
7.8
First published (updated )

Mako: Path traversal via backslash URI on Windows in TemplateLookup

Risk 47
Severity
8.7
First published (updated )

jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content

Risk 80
Severity
8.6
First published (updated )

GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository

Risk 62
Severity
7.8
First published (updated )

basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering

Risk 43
Severity
7.5
First published (updated )

Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles

Risk 47
Severity
8.7
First published (updated )

JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.

Risk 79
Severity
8.8
First published (updated )

net-imap: Command Injection via "raw" arguments to multiple commands

Risk 86
Severity
5.8
First published (updated )

net-imap: Command Injection via unvalidated Symbol inputs

Risk 47
Severity
5.8
First published (updated )

Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2)

Risk 86
Severity
9.8
First published (updated )

Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE (take 2)

Risk 86
Severity
9.8
First published (updated )

Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker

Risk 70
Severity
8.4
First published (updated )

Denial of service in static resource handling on Windows platforms

Risk 27
Severity
5.3
First published (updated )

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write acc…

Risk 60
Severity
6.7
First published (updated )

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized ac…

Risk 66
Severity
9.1
First published (updated )

Weak RNG

Risk 54
Severity
8.2
First published (updated )

A local attacker on the same host as the application may be able to take control of the directory us…

Risk 63
Severity
7
First published (updated )

Apache MINA: CWE-502 Deserialization of Untrusted Data

Risk 91
Severity
9.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203