Vulnerabilities

Summary — last 7 days

New vulnerabilities2,729▼ 513 vs. last week
Critical / high1,298▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
–

30 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (6.1)0.20%—IBM Common Licensing AgentAIIBM ARTAI9/18/20269/18/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
Awaiting AnalysisMedium (6.1)0.20%—IBM Common Licensing AgentAIIBM ARTAI9/18/20269/19/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
Awaiting AnalysisMedium (4.3)0.21%—IBM Common Licensing AgentAIIBM ARTAI9/18/20269/19/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.
Awaiting AnalysisMedium (5.4)0.16%—IBM Common Licensing AgentAIIBM ARTAI9/18/20269/18/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
Awaiting AnalysisMedium (6.1)0.18%—IBM Common Licensing AgentAIIBM ARTAI9/18/20269/19/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
Awaiting AnalysisCritical (10)0.18%—IBM Common Licensing AgentAIIBM ARTAI9/18/20269/21/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
DeferredHigh (8.1)0.62%—Labs64 Netlicensing MCP ServerAI9/17/20269/30/2026
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass…
Awaiting AnalysisMedium (6.2)0.12%—IBM Common Licensing AgentAIIBM ARTAI9/14/20269/16/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values,…
Awaiting AnalysisCritical (9.1)0.38%—IBM Common Licensing AgentAIIBM ARTAI9/10/20269/11/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
DeferredHigh (8.4)0.14%—IBM Licensing OperatorAI1/20/20266/17/2026
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.
DeferredHigh (8.7)0.23%—Nvidia Delegated Licensing ServiceAI9/30/20256/17/2026
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.
DeferredMedium (4.6)0.22%—Nvidia Delegated Licensing ServiceAI9/30/20256/17/2026
NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to partial denial of service (UI component).
DeferredLow (2.4)0.13%—Nvidia Delegated Licensing ServiceAI9/30/20256/17/2026
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.
AnalyzedMedium (6.5)0.27%—IBM Common Licensing1/26/20256/17/2026
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.
AnalyzedMedium (5.5)0.14%—IBM Common Licensing1/26/20256/17/2026
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
DeferredHigh (7.6)0.25%—Nvidia Delegated Licensing ServiceAI11/23/20246/17/2026
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. A successful exploit of this vulnerability may lead to partial denial of service and confidential information disclosure.
ModifiedMedium (4.8)0.26%—IBM Common Licensing8/13/20246/17/2026
IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348.
AnalyzedHigh (7.5)0.49%—IBM Common Licensing8/13/20246/17/2026
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
AnalyzedMedium (5.3)0.49%—Xwiki Application Licensing2/21/20246/17/2026
The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON` that provides information for admins regarding active licenses. This document is public and thus exposes this information publicly. The information includes the…
AnalyzedLow (3.3)0.19%—IBM Common Licensing2/20/20246/17/2026
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.
ModifiedHigh (7.1)0.22%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+911/15/20236/17/2026
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
ModifiedHigh (7.8)0.24%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+911/15/20236/17/2026
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
ModifiedHigh (7.8)0.24%—Autodesk Licensing Services5/28/20216/17/2026
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and are running under elevated privileges. These weak permissions could allow all…
ModifiedHigh (7.1)0.62%💥 PoCNalpeiron Licensing Service12/17/20196/17/2026
NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \\.\mailslot\nlsX86ccMailslot mailslot.
ModifiedMedium (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads Software Licensing10/23/20196/17/2026
The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Orbitaley — Vulnerabilities