Where
-Infinity
0

IBM API Connect V12 OnPrem29 vulnerabilities

First published (updated )
Advisory
IBM-7278909

IBM API Connect Default Credentials

Risk 86
Severity
9.8
First published (updated )

Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)

Risk 76
Severity
7.5
First published (updated )

Apache CXF: XXE vulnerability in WS-Transfer functionality

Risk 29
Severity
5.3
First published (updated )

Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository

Risk 92
Severity
9.8
First published (updated )

Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

Risk 82
Severity
8.7
First published (updated )

opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

Risk 43
Severity
7.5
First published (updated )

protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion

Risk 43
Severity
7.5
First published (updated )

Apache Tomcat: Security constraints not correctly applied

Risk 71
Severity
9.1
First published (updated )

Apache Tomcat: AJP secret compared in non-constant time

Risk 22
Severity
3.7
First published (updated )

Apache Tomcat: LockOutRealm treats user names as case-sensitive

Risk 46
Severity
7.5
First published (updated )

Apache Tomcat: Digest authenticator will authenticate any unknown user

Risk 92
Severity
9.8
First published (updated )

Apache Tomcat: HTTP/2 request headers not validated

Risk 92
Severity
9.8
First published (updated )

Apache Tomcat: WebSocket authentication header exposure

Risk 55
Severity
7.3
First published (updated )

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Risk 46
Severity
7.5
First published (updated )

opentelemetry-js: Prometheus exporter process crash via malformed HTTP request

Risk 43
Severity
7.5
First published (updated )

i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite

Risk 54
Severity
8.2
First published (updated )

Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)

Risk 66
Severity
9.1
First published (updated )

Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

Risk 43
Severity
2.9
First published (updated )

Netty: epoll transport denial of service via RST on half-closed TCP connection

Risk 43
Severity
7.5
First published (updated )

GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

Risk 69
Severity
7.8
First published (updated )

Python-Multipart: Denial of Service via unbounded multipart part headers

Risk 43
Severity
7.5
First published (updated )

Mako: Path traversal via backslash URI on Windows in TemplateLookup

Risk 47
Severity
8.7
First published (updated )

jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content

Risk 80
Severity
8.6
First published (updated )

GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository

Risk 62
Severity
7.8
First published (updated )

basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering

Risk 43
Severity
7.5
First published (updated )

Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles

Risk 47
Severity
8.7
First published (updated )

JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.

Risk 79
Severity
8.8
First published (updated )

net-imap: Command Injection via "raw" arguments to multiple commands

Risk 86
Severity
5.8
First published (updated )

net-imap: Command Injection via unvalidated Symbol inputs

Risk 47
Severity
5.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203