ENISA EUVD · EUVD-2025-205660Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-3046IBM Concert: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-1194Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-0177Atlassian Bamboo, Bitbucket, Confluence und Jira: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, und um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0759IBM Planning Analytics: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Planning Analytics ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-0301IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of ServiceEin entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0243Red Hat OpenShift Container Platform: Schwachstelle ermöglicht Denial of ServiceEin entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift Container Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0181ILIAS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in ILIAS ausnutzen, um einen Denial of Service Angriff durchzuführen, und um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0105Red Hat Developer Hub: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Developer Hub ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.
Official advisory ↗BSI · German · WID-SEC-2026-0943IBM DataPower Gateway: Schwachstelle ermöglicht Denial of ServiceEin entfernter, anonymer Angreifer kann eine Schwachstelle in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20251231Security Bulletin 31 Dec 2025The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 31 Dec 2025, published on 31 December 2025. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMord?id=CVE-2020-15366
Référence CVE CVE-2021-23337
https://www.cve.org/CVERecord?id=CVE-2021-23337
Référence CVE CVE-2022-24999
https://www.cve.org/CVERecord?id=CVE-2022-24999
Référence CVE CVE-2022-3517
https://www.cve.org/CVERecord?id=CVE-2022-3517
Référence CVE CVE-2024-55565
https://www.cve.org/CVERecord?id=CVE-2024-55565
Référence CVE CVE-2024-56602
https://www.cve.org/CVERecord?id=CVE-2024-56602
Référence CVE CVE-2024-57849
https://www.cve.org/CVERecord?id=CVE-2024-57849
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-27152
https://www.cve.org/CVERecord?id=CVE-2025-27152
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-39902
https://www.cve.org/CVERecord?id=CVE-2025-39902
Référence CVE CVE-2025-4330
https://www.cve.org/CVERecord?id=CVE-2025-4330
Référence CVE CVE-2025-46653
https://www.cve.org/CVERecord?id=CVE-2025-46653
Référence CVE CVE-2025-54518
https://www.cve.org/CVERecord?id=CVE-2025-54518
Référence CVE CVE-2025-58754
https://www.cve.org/CVERecord?id=CVE-2025-58754
Référence CVE CVE-2025-5889
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-45337
Référence CVE CVE-2024-52046
https://www.cve.org/CVERecord?id=CVE-2024-52046
Référence CVE CVE-2024-6763
https://www.cve.org/CVERecord?id=CVE-2024-6763
Référence CVE CVE-2025-11143
https://www.cve.org/CVERecord?id=CVE-2025-11143
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-12183
https://www.cve.org/CVERecord?id=CVE-2025-12183
Référence CVE CVE-2025-12758
https://www.cve.org/CVERecord?id=CVE-2025-12758
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-21502
https://www.cve.org/CVERecord?id=CVE-2025-21502
Référence CVE CVE-2025-22228
https://www.cve.org/CVERecord?id=CVE-2025-22228
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-47935
https://www.cve.org/CVERecord?id=CVE-2025-47935
Référence CVE CVE-2025-47944
https://www.cve.org/CVERecord?id=CVE-2025-47944
Référence CVE CVE-2025-48387
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-37891
Référence CVE CVE-2024-39689
https://www.cve.org/CVERecord?id=CVE-2024-39689
Référence CVE CVE-2024-45337
https://www.cve.org/CVERecord?id=CVE-2024-45337
Référence CVE CVE-2024-47081
https://www.cve.org/CVERecord?id=CVE-2024-47081
Référence CVE CVE-2024-52804
https://www.cve.org/CVERecord?id=CVE-2024-52804
Référence CVE CVE-2024-6485
https://www.cve.org/CVERecord?id=CVE-2024-6485
Référence CVE CVE-2025-11143
https://www.cve.org/CVERecord?id=CVE-2025-11143
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-14505
https://www.cve.org/CVERecord?id=CVE-2025-14505
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15599
https://www.cve.org/CVERecord?id=CVE-2025-15599
Référence CVE CVE-2025-23165
https://www.cve.org/CVERecord?id=CVE-2025-23165
Référence CVE CVE-2025-47287
https://www.cve.org/CVERecord?id=CVE-2025-47287
Référence CVE CVE-2025-50181
https://www.cve.org/CVERecord?id=CVE-2025-50181
Référence CVE CVE-2025-59436
https://www.cve.org/CVERecord?id=CVE-2025-59436
Référence CVE CVE-2025-59437
https://www.cve.org/CVERecord?id=CVE-2025-59437
Référence CVE CVE-2025-59471
https://www.cve.org/CVERecord?id=CVE-2025-59471
Référence CVE CVE-2025-59472
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0834Multiples vulnérabilités dans les produits IBMCVERecord?id=CVE-2024-29869
Référence CVE CVE-2024-7531
https://www.cve.org/CVERecord?id=CVE-2024-7531
Référence CVE CVE-2025-12183
https://www.cve.org/CVERecord?id=CVE-2025-12183
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-1371
https://www.cve.org/CVERecord?id=CVE-2025-1371
Référence CVE CVE-2025-13755
https://www.cve.org/CVERecord?id=CVE-2025-13755
Référence CVE CVE-2025-1376
https://www.cve.org/CVERecord?id=CVE-2025-1376
Référence CVE CVE-2025-1377
https://www.cve.org/CVERecord?id=CVE-2025-1377
Référence CVE CVE-2025-14688
https://www.cve.org/CVERecord?id=CVE-2025-14688
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-1795
https://www.cve.org/CVERecord?id=CVE-2025-1795
Référence CVE CVE-2025-36122
https://www.cve.org/CVERecord?id=CVE-2025-36122
Référence CVE CVE-2025-4516
https://www.cve.org/CVERecord?id=CVE-2025-4516
Référence CVE CVE-2025-47914
https://www.cve.org/CVERecord?id=CVE-2025-47914
Référence CVE CVE-2025-48924
https://www.cve.org/CVERecord?id=CVE-2025-48924
Référence CVE CVE-2025-50181
https://www.cve.org/CVERecord?id=CVE-2025-50181
Référence CVE CVE-2025-50182
https://www.cve.org/CVERecord?id=CVE-2025-50182
Référence CVE CVE-2025-58181
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0667Multiples vulnérabilités dans les produits IBMrd?id=CVE-2024-9902
Référence CVE CVE-2025-11953
https://www.cve.org/CVERecord?id=CVE-2025-11953
Référence CVE CVE-2025-12635
https://www.cve.org/CVERecord?id=CVE-2025-12635
Référence CVE CVE-2025-12758
https://www.cve.org/CVERecord?id=CVE-2025-12758
Référence CVE CVE-2025-12816
https://www.cve.org/CVERecord?id=CVE-2025-12816
Référence CVE CVE-2025-13333
https://www.cve.org/CVERecord?id=CVE-2025-13333
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-14009
https://www.cve.org/CVERecord?id=CVE-2025-14009
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-40252
https://www.cve.org/CVERecord?id=CVE-2025-40252
Référence CVE CVE-2025-41248
https://www.cve.org/CVERecord?id=CVE-2025-41248
Référence CVE CVE-2025-41249
https://www.cve.org/CVERecord?id=CVE-2025-41249
Référence CVE CVE-2025-5187
https://www.cve.org/CVERecord?id=CVE-2025-5187
Référence CVE CVE-2025-53643
https://www.cve.org/CVERecord?id=CVE-2025-53643
Référence CVE CVE-2025-58754
https://www.cve.org/CVERecord?id=CVE-2025-58754
Référence CVE CVE-2025-59471
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0641Multiples vulnérabilités dans les produits IBMd?id=CVE-2021-43784
Référence CVE CVE-2023-47038
https://www.cve.org/CVERecord?id=CVE-2023-47038
Référence CVE CVE-2024-45310
https://www.cve.org/CVERecord?id=CVE-2024-45310
Référence CVE CVE-2024-47072
https://www.cve.org/CVERecord?id=CVE-2024-47072
Référence CVE CVE-2024-50301
https://www.cve.org/CVERecord?id=CVE-2024-50301
Référence CVE CVE-2025-12801
https://www.cve.org/CVERecord?id=CVE-2025-12801
Référence CVE CVE-2025-13867
https://www.cve.org/CVERecord?id=CVE-2025-13867
Référence CVE CVE-2025-14689
https://www.cve.org/CVERecord?id=CVE-2025-14689
Référence CVE CVE-2025-14831
https://www.cve.org/CVERecord?id=CVE-2025-14831
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-21614
https://www.cve.org/CVERecord?id=CVE-2025-21614
Référence CVE CVE-2025-22227
https://www.cve.org/CVERecord?id=CVE-2025-22227
Référence CVE CVE-2025-2668
https://www.cve.org/CVERecord?id=CVE-2025-2668
Référence CVE CVE-2025-27221
https://www.cve.org/CVERecord?id=CVE-2025-27221
Référence CVE CVE-2025-32988
https://www.cve.org/CVERecord?id=CVE-2025-32988
Référence CVE CVE-2025-32989
https://www.cve.org/CVERecord?id=CVE-2025-32989
Référence CVE CVE-2025-32990
https://www.cve.org/CVERecord?id=CVE-2025-32990
Référence CVE CVE-2025-33042
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0523Multiples vulnérabilités dans les produits IBMw.ibm.com/support/pages/node/7270827
Bulletin de sécurité IBM 7270845 du 27 avril 2026
https://www.ibm.com/support/pages/node/7270845
Bulletin de sécurité IBM 7270868 du 27 avril 2026
https://www.ibm.com/support/pages/node/7270868
Bulletin de sécurité IBM 7270869 du 27 avril 2026
https://www.ibm.com/support/pages/node/7270869
Référence CVE CVE-2021-23337
https://www.cve.org/CVERecord?id=CVE-2021-23337
Référence CVE CVE-2024-29371
https://www.cve.org/CVERecord?id=CVE-2024-29371
Référence CVE CVE-2024-31033
https://www.cve.org/CVERecord?id=CVE-2024-31033
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15599
https://www.cve.org/CVERecord?id=CVE-2025-15599
Référence CVE CVE-2025-66035
https://www.cve.org/CVERecord?id=CVE-2025-66035
Référence CVE CVE-2025-66412
https://www.cve.org/CVERecord?id=CVE-2025-66412
Référence CVE CVE-2025-67030
https://www.cve.org/CVERecord?id=CVE-2025-67030
Référence CVE CVE-2025-68470
https://www.cve.org/CVERecord?id=CVE-2025-68470
Référence CVE CVE-2026-0540
https://www.cve.org/CVERecord?id=CVE-2026-0540
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-22610
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0281Multiples vulnérabilités dans les produits Splunkd?id=CVE-2025-13227
Référence CVE CVE-2025-13228
https://www.cve.org/CVERecord?id=CVE-2025-13228
Référence CVE CVE-2025-13229
https://www.cve.org/CVERecord?id=CVE-2025-13229
Référence CVE CVE-2025-13230
https://www.cve.org/CVERecord?id=CVE-2025-13230
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-14087
https://www.cve.org/CVERecord?id=CVE-2025-14087
Référence CVE CVE-2025-14104
https://www.cve.org/CVERecord?id=CVE-2025-14104
Référence CVE CVE-2025-14512
https://www.cve.org/CVERecord?id=CVE-2025-14512
Référence CVE CVE-2025-14874
https://www.cve.org/CVERecord?id=CVE-2025-14874
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-1594
https://www.cve.org/CVERecord?id=CVE-2025-1594
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22872
https://www.cve.org/CVERecord?id=CVE-2025-22872
Référence CVE CVE-2025-22874
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0249Multiples vulnérabilités dans les produits IBMrg/CVERecord?id=CVE-2024-6531
Référence CVE CVE-2024-7143
https://www.cve.org/CVERecord?id=CVE-2024-7143
Référence CVE CVE-2024-8176
https://www.cve.org/CVERecord?id=CVE-2024-8176
Référence CVE CVE-2024-8184
https://www.cve.org/CVERecord?id=CVE-2024-8184
Référence CVE CVE-2024-9042
https://www.cve.org/CVERecord?id=CVE-2024-9042
Référence CVE CVE-2025-0426
https://www.cve.org/CVERecord?id=CVE-2025-0426
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-13867
https://www.cve.org/CVERecord?id=CVE-2025-13867
Référence CVE CVE-2025-14689
https://www.cve.org/CVERecord?id=CVE-2025-14689
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-1767
https://www.cve.org/CVERecord?id=CVE-2025-1767
Référence CVE CVE-2025-21587
https://www.cve.org/CVERecord?id=CVE-2025-21587
Référence CVE CVE-2025-21613
https://www.cve.org/CVERecord?id=CVE-2025-21613
Référence CVE CVE-2025-21905
https://www.cve.org/CVERecord?id=CVE-2025-21905
Référence CVE CVE-2025-22085
https://www.cve.org/CVERecord?id=CVE-2025-22085
Référence CVE CVE-2025-22091
https://www.cve.org/CVERecord?id=CVE-2025-22091
Référence CVE CVE-2025-22113
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0224Multiples vulnérabilités dans les produits IBM2026
https://www.ibm.com/support/pages/node/7261890
Bulletin de sécurité IBM 7261935 du 26 février 2026
https://www.ibm.com/support/pages/node/7261935
Bulletin de sécurité IBM 7261959 du 26 février 2026
https://www.ibm.com/support/pages/node/7261959
Référence CVE CVE-2023-53673
https://www.cve.org/CVERecord?id=CVE-2023-53673
Référence CVE CVE-2024-29371
https://www.cve.org/CVERecord?id=CVE-2024-29371
Référence CVE CVE-2025-12816
https://www.cve.org/CVERecord?id=CVE-2025-12816
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-14847
https://www.cve.org/CVERecord?id=CVE-2025-14847
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-39993
https://www.cve.org/CVERecord?id=CVE-2025-39993
Référence CVE CVE-2025-40154
https://www.cve.org/CVERecord?id=CVE-2025-40154
Référence CVE CVE-2025-40240
https://www.cve.org/CVERecord?id=CVE-2025-40240
Référence CVE CVE-2025-40248
https://www.cve.org/CVERecord?id=CVE-2025-40248
Référence CVE CVE-2025-40277
https://www.cve.org/CVERecord?id=CVE-2025-40277
Référence CVE CVE-2025-61140
https://www.cve.org/CVERecord?id=CVE-2025-61140
Référence CVE CVE-2025-64756
https://www.cve.org/CVERecord?id=CVE-2025-64756
Référence CVE CVE-2025-65106
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0196Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0188Multiples vulnérabilités dans les produits Splunkde sécurité Splunk SVD-2026-0208 du 18 février 2026
https://advisory.splunk.com/advisories/SVD-2026-0208
Bulletin de sécurité Splunk SVD-2026-0209 du 18 février 2026
https://advisory.splunk.com/advisories/SVD-2026-0209
Bulletin de sécurité Splunk SVD-2026-0210 du 18 février 2026
https://advisory.splunk.com/advisories/SVD-2026-0210
Bulletin de sécurité Splunk SVD-2026-0211 du 18 février 2026
https://advisory.splunk.com/advisories/SVD-2026-0211
Bulletin de sécurité Splunk SVD-2026-0212 du 18 février 2026
https://advisory.splunk.com/advisories/SVD-2026-0212
Référence CVE CVE-2025-0913
https://www.cve.org/CVERecord?id=CVE-2025-0913
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22874
https://www.cve.org/CVERecord?id=CVE-2025-22874
Référence CVE CVE-2025-23166
https://www.cve.org/CVERecord?id=CVE-2025-23166
Référence CVE CVE-2025-27210
https://www.cve.org/CVERecord?id=CVE-2025-27210
Référence CVE CVE-2025-4673
https://www.cve.org/CVERecord?id=CVE-2025-4673
Référence CVE CVE-2025-47906
https://www.cve.org/CVERecord?id=CVE-2025-47906
Référence CVE CVE-2025-47907
https://www.cve.org/CVERecord?id=CVE-2025-47907
Référence CVE CVE-2025-47912
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0171Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0112Multiples vulnérabilités dans les produits VMwared?id=CVE-2025-11413
Référence CVE CVE-2025-11414
https://www.cve.org/CVERecord?id=CVE-2025-11414
Référence CVE CVE-2025-11494
https://www.cve.org/CVERecord?id=CVE-2025-11494
Référence CVE CVE-2025-12817
https://www.cve.org/CVERecord?id=CVE-2025-12817
Référence CVE CVE-2025-12818
https://www.cve.org/CVERecord?id=CVE-2025-12818
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-14087
https://www.cve.org/CVERecord?id=CVE-2025-14087
Référence CVE CVE-2025-14512
https://www.cve.org/CVERecord?id=CVE-2025-14512
Référence CVE CVE-2025-14762
https://www.cve.org/CVERecord?id=CVE-2025-14762
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-21855
https://www.cve.org/CVERecord?id=CVE-2025-21855
Référence CVE CVE-2025-22228
https://www.cve.org/CVERecord?id=CVE-2025-22228
Référence CVE CVE-2025-22233
https://www.cve.org/CVERecord?id=CVE-2025-22233
Référence CVE CVE-2025-22235
https://www.cve.org/CVERecord?id=CVE-2025-22235
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22869
https://www.cve.org/CVERecord?id=CVE-2025-22869
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0065Multiples vulnérabilités dans les produits AtlassianDe multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2025-026171qs projectのqsにおける入力確認に関する脆弱性qs(parseモジュール)の不適切な入力検証の脆弱性によりHTTP DoSが発生します。この問題はqsのバージョン6.14.1未満に影響します。概要として、qsのarrayLimitオプションは角括弧表記(a[]=1&a[]=2)には制限を適用せず、インデックス表記(a[0]=1)にのみ制限を適用していました。これは一貫性のバグであり、arrayLimitはすべての配列表記に均一に適用されるべきです。注意点として、デフォルトのparameterLimit(1000)が当初説明されたDoSシナリオを実質的に軽減します。デフォルトオプションでは、角括弧表記はarrayLimitに関わらずparameterLimitを超える配列を生成できません。これは各a[]=valueが1つのパラメータスロットを消費するためです。このため、深刻度は適宜軽減されています。詳細として、arrayLimitオプションはインデックス表記(a[0]=1&a[1]=2)にのみ制限をチェックし、角括弧表記(a[]=1&a[]=2)には適用していませんでした。脆弱なコード(lib/parse.js:159-162)は、if (root === '[]' && options.parseArrays) {obj = utils.combine([], leaf); // arrayLimitチェックなし}となっており、動作コード(lib/parse.js:175)はelse if (index = options.arrayLimit) {obj = []; obj[index] = leaf;}と記述されています。角括弧表記のハンドラ(159行目)はoptions.arrayLimitを検証せずにutils.combine([], leaf)を使用していますが、インデックス表記(175行目)はindex = options.arrayLimitをチェックしています。PoCは以下の通りです:const qs = require('qs'); const result = qs.parse('a[]=1&a[]=2&a[]=3&a[]=4&a[]=5&a[]=6', {arrayLimit: 5}); console.log(result.a.length); // 出力:6(最大5であるべき)。パラメータ制限の注意点として、元の勧告のDoSデモは長さ10,000と主張しましたが、parameterLimit(デフォルト1000)が解析パラメータを最大1,000に制限します。デフォルト設定の場合、実際の出力は10,000ではなく1,000になります。影響としては、arrayLimit適用の一貫性のバグであり、デフォルトのparameterLimitが既に解析パラメータ数(および角括弧表記からの配列要素数)を制限しているため、実際のDoSリスクはほとんどありません。リスクはparameterLimitを非常に高く設定した場合にのみ増加します。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0079Kwetsbaarheden verholpen in Siemens productenThe qs library's `arrayLimit` option fails to enforce limits on bracket notation arrays, enabling denial-of-service attacks via memory exhaustion by parsing large arrays from user input.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0034Kwetsbaarheden verholpen in Atlassian productenThe `qs` module's `arrayLimit` option is vulnerable to denial-of-service attacks due to its failure to enforce limits for bracket notation, allowing attackers to exploit memory exhaustion.
Official advisory ↗