| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-14923 | IBM WebSphere Application Server Liberty could provide weaker than expected security | IBM | WebSphere Application Server - Liberty | Medium | 4.7 | 2026-03-03 19:47:25 | Deep Dive |
| CVE-2026-0871 | Org.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administrators | Red Hat | Red Hat build of Keycloak 26.4 | Medium | 4.9 | 2026-02-27 07:30:27 | Deep Dive |
| CVE-2026-20107 | Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability | Cisco | Cisco Application Policy Infrastructure Controller (APIC) | Medium | 5.5 | 2026-02-25 16:14:34 | Deep Dive |
| CVE-2025-1242 | Administrative Credentials Can Be Extracted Through Gardyn API Responses | Gardyn | Home Kit | Critical | 9.1 | 2026-02-25 15:21:48 | Deep Dive |
| CVE-2026-2733 | Org.keycloak/keycloak-services: keycloak: missing check on disabled client for docker registry protocol | Red Hat | Red Hat build of Keycloak 26.4 | Low | 3.8 | 2026-02-19 07:48:09 | Deep Dive |
| CVE-2025-13333 | IBM WebSphere Application Server could provide weaker than expected security | IBM | WebSphere Application Server | Medium | 4.4 | 2026-02-17 22:45:11 | Deep Dive |
| CVE-2025-2418 | Open Redirect in TR7's Web Application Firewall | TR7 Cyber Defense Inc. | Web Application Firewall | Medium | 4.3 | 2026-02-16 11:47:34 | Deep Dive |
| CVE-2026-2276 | Reflected Cross-Site Scripting in the Wix web application | Wix | web application | - | - | 2026-02-12 10:26:04 | Deep Dive |
| CVE-2025-12699 | ZOLL ePCR IOS Mobile Application Insertion of Sensitive Information into Externally-Accessible File or Directory | ZOLL | ZOLL ePCR IOS Mobile Application | Medium | 5.5 | 2026-02-10 20:38:38 | Deep Dive |
| CVE-2026-24328 | Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER) | SAP_SE | Business Server Pages Application (TAF_APPLAUNCHER) | Medium | 6.1 | 2026-02-10 03:04:55 | Deep Dive |
| CVE-2026-24327 | Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application) | SAP_SE | SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application) | Medium | 4.3 | 2026-02-10 03:04:47 | Deep Dive |
| CVE-2026-24320 | Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP) | SAP_SE | SAP NetWeaver and ABAP Platform (Application Server ABAP) | Low | 3.1 | 2026-02-10 03:03:43 | Deep Dive |
| CVE-2026-23686 | CRLF Injection vulnerability in SAP NetWeaver Application Server Java | SAP_SE | SAP NetWeaver Application Server Java | Low | 3.4 | 2026-02-10 03:02:37 | Deep Dive |
| CVE-2026-0509 | Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform | SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | Critical | 9.6 | 2026-02-10 03:01:53 | Deep Dive |
| CVE-2026-0484 | Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA | SAP_SE | SAP NetWeaver Application Server ABAP and SAP S/4HANA | Medium | 6.5 | 2026-02-10 03:00:41 | Deep Dive |
| CVE-2026-2172 | code-projects Online Application System for Admission Login Endpoint index.php sql injection | code-projects | Online Application System for Admission | High | 7.3 | 2026-02-08 18:02:09 | Deep Dive |
| CVE-2019-25266 | Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path | Wondershare | Wondershare Application Framework Service | High | 7.8 | 2026-02-06 16:41:34 | Deep Dive |
| CVE-2025-14914 | IBM WebSphere Application Server Liberty Path Traversal | IBM | WebSphere Application Server Liberty | High | 7.6 | 2026-02-02 15:17:57 | Deep Dive |
| CVE-2020-37048 | Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path | Iskysoft | Iskysoft Application Framework Service | High | 7.8 | 2026-02-01 14:38:28 | Deep Dive |
| CVE-2024-4027 | Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacks | Red Hat | OpenShift Serverless | High | 7.5 | 2026-01-30 14:25:54 | Deep Dive |