Vulnerabilities
Vulnerable Software
Security Vulnerabilities
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.
CVSS Score
6.1
EPSS Score
0.001
Published
2026-09-23
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
CVSS Score
9.8
EPSS Score
0.005
Published
2026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
CVSS Score
9.8
EPSS Score
0.005
Published
2026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
CVSS Score
9.9
EPSS Score
0.005
Published
2026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-09-22
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection.
CVSS Score
8.8
EPSS Score
0.017
Published
2026-09-22
IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS Score
8.8
EPSS Score
0.01
Published
2026-09-22
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-09-22
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-09-22


Contact Us

Shodan ® - All rights reserved