Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · tibco

tibco

· 26 Critical

Total CVEs

226

Critical

26

Products

179

Search All CVEs →

226

Products (179)

spotfire server28 CVEsjasperreports server22 CVEsspotfire analytics platform for aws20 CVEsrendezvous16 CVEsspotfire analyst12 CVEsenterprise message service11 CVEsspotfire desktop10 CVEsmanaged file transfer command center10 CVEsmanaged file transfer internet server10 CVEsjaspersoft reporting and analytics10 CVEsjaspersoft10 CVEsebx add-ons9 CVEsftl9 CVEsebx9 CVEsruntime agent9 CVEsactivematrix bpm8 CVEsactivematrix service bus8 CVEsactivematrix service grid8 CVEsspotfire deployment kit8 CVEsspotfire analytics platform7 CVEsspotfire statistics services7 CVEssilver fabric enabler7 CVEsspotfire desktop language packs6 CVEsadministrator6 CVEshawk6 CVEsslingshot5 CVEssmartsockets rtserver5 CVEsjasperreports library5 CVEseftl5 CVEsrtworks5 CVEsactivematrix businessworks service engine5 CVEsiprocess engine5 CVEsspotfire web player5 CVEsactivecatalog4 CVEsenterprise runtime for r4 CVEsmessaging appliance4 CVEsnimbus4 CVEspartnerexpress4 CVEsbusinessconnect4 CVEsspotfire analytics server4 CVEsspotfire professional4 CVEscollaborative information manager4 CVEssubstantiation es4 CVEsdata virtualization4 CVEsbusinessconnect trading community management3 CVEsactivespaces3 CVEsproduct and service catalog powered by tibco ebx3 CVEsspotfire data science3 CVEsbpm enterprise3 CVEsmanaged file transfer platform server3 CVEsdata science for aws3 CVEsactivematrix policy director3 CVEsactivematrix businessworks3 CVEsdata virtualization for aws marketplace3 CVEsdatasynapse gridserver manager3 CVEstibbr3 CVEsvault3 CVEssilver fabric activematrix service grid distribution3 CVEsapi exchange gateway2 CVEssilver cap service2 CVEsdata science - workbench2 CVEsems server2 CVEsiprocess workspace2 CVEsactivematrix business process management2 CVEssilver bpm service2 CVEsrendezvous network server2 CVEsbpm enterprise distribution for silver fabric2 CVEsstatistica2 CVEsjaspersoft studio2 CVEsspotfire automation services2 CVEsiway service manager2 CVEsspotfire connectors2 CVEssmart pgm fx2 CVEssilver fabric2 CVEsoperational intelligence hawk redtail2 CVEssubstation es2 CVEsloglogic st40351 CVEsloglogic st4035 firmware1 CVEsloglogic unity1 CVEsmainframe service tracker1 CVEsmaster data management1 CVEsmessaging - apache kafka distribution - schema repository1 CVEsmessaging - eclipse mosquitto distribution - bridge1 CVEsmessaging - eclipse mosquitto distribution - core1 CVEspatterns - search1 CVEsrendezvous datasecurity1 CVEsrendezvous for z\/linux1 CVEsrendezvous for z\/os1 CVEsrendezvous tx1 CVEssilver businessworks service1 CVEssilver fabric enabler for spotfire web player1 CVEssilver fabric enabler for spotfire webplayer1 CVEssilver mobile1 CVEssmartsockets1 CVEsspotfire client1 CVEsspotfire enterprise runtime for r1 CVEsspotfire web player client1 CVEsstatistica server1 CVEstibbr service1 CVEsweb player1 CVEsweb player automation services1 CVEswebfocus client1 CVEswebfocus installer1 CVEswebfocus reporting server1 CVEsactivematrix businessworks distribution for tibco silver fabric1 CVEsactivematrix management agent1 CVEsactivematrix policy agent1 CVEsactivematrix policy manager1 CVEsactivematrix service performance manager1 CVEsadapter files z os1 CVEsanalyst1 CVEsanalytics platform1 CVEsapi exchange gateway distribution1 CVEsauditsafe1 CVEsautomation services1 CVEsbusinessevents1 CVEsbusinessworks buildpack1 CVEsbusinessworks process monitor1 CVEsdeployment kit1 CVEsdesktop1 CVEsenterprise administrator1 CVEsenterprise administrator sdk1 CVEsenterprise message service appliance1 CVEsenterprise message service appliance firmware1 CVEsforesight archive and retrieval system1 CVEsforesight operational monitor1 CVEsforesight transaction insight1 CVEsformvine1 CVEshawk distribution for tibco silver fabric1 CVEshawk monitoring agent1 CVEsiprocess workspace browser1 CVEsjasperreports library community edition1 CVEsjasperreports library for activematrix bpm1 CVEsjasperreports professional1 CVEsjasperreports server community edition1 CVEsjasperreports server for activematrix bpm1 CVEsjaspersoft for aws with multi-tenancy1 CVEsjaspersoft reporting and analytics for aws1 CVEsjaspersoft studio for activematrix bpm1 CVEsloglogic enterprise virtual appliance1 CVEsloglogic log management intelligence1 CVEsloglogic lx10251 CVEsloglogic lx1025 firmware1 CVEsloglogic lx1025r11 CVEsloglogic lx1025r1 firmware1 CVEsloglogic lx1025r21 CVEsloglogic lx1025r2 firmware1 CVEsloglogic lx10351 CVEsloglogic lx1035 firmware1 CVEsloglogic lx40251 CVEsloglogic lx4025 firmware1 CVEsloglogic lx4025r11 CVEsloglogic lx4025r1 firmware1 CVEsloglogic lx4025r21 CVEsloglogic lx4025r2 firmware1 CVEsloglogic lx40351 CVEsloglogic lx4035 firmware1 CVEsloglogic lx8251 CVEsloglogic lx825 firmware1 CVEsloglogic mx30251 CVEsloglogic mx3025 firmware1 CVEsloglogic mx40251 CVEsloglogic mx4025 firmware1 CVEsloglogic st10251 CVEsloglogic st1025 firmware1 CVEsloglogic st2025-san1 CVEsloglogic st2025-san firmware1 CVEsloglogic st2025-sanr11 CVEsloglogic st2025-sanr1 firmware1 CVEsloglogic st2025-sanr21 CVEsloglogic st2025-sanr2 firmware1 CVEsloglogic st2035-san1 CVEsloglogic st2035-san firmware1 CVEsloglogic st40251 CVEsloglogic st4025 firmware1 CVEsloglogic st4025r11 CVEsloglogic st4025r1 firmware1 CVEsloglogic st4025r21 CVEsloglogic st4025r2 firmware1 CVEs

Recent Vulnerabilities

View all 226
CVE-2026-3207CRITICAL 9.8

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

CVE-2025-3115CRITICAL 9.8

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

CVE-2024-4576MEDIUM 5.3

The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.

CVE-2023-26222HIGH 8.7

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.

CVE-2023-26221MEDIUM 5.0

The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.

CVE-2023-26219HIGH 7.4

The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.

CVE-2023-26220MEDIUM 5.4

The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.

CVE-2023-26218HIGH 8.0

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.6.0 and below.

CVE-2023-26217HIGH 8.8

The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0.

CVE-2023-26216CRITICAL 9.1

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.

CVE-2023-26215HIGH 7.7

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that are accessible to the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.

CVE-2023-29268CRITICAL 9.8

The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.

CVE-2023-26214HIGH 7.3

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-41567HIGH 7.3

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2022-41566HIGH 8.7

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.6.0 and below.

CVE-2022-41565HIGH 8.7

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.

CVE-2022-41564MEDIUM 6.8

The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO Operational Intelligence Hawk RedTail: versions 7.0.0 through 7.2.0.

CVE-2022-41563CRITICAL 9.0

The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 8.0.2 and below, TIBCO JasperReports Server: version 8.1.0, TIBCO JasperReports Server - Developer Edition: versions 8.1.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 8.0.2 and below, TIBCO JasperReports Server for AWS Marketplace: version 8.1.0, TIBCO JasperReports Server for Microsoft Azure: versions 8.0.2 and below, and TIBCO JasperReports Server for Microsoft Azure: version 8.1.0.

CVE-2022-41562HIGH 8.4

The HTML escaping component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows a privileged/administrative attacker with network access to execute an XSS attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 8.0.2 and below, TIBCO JasperReports Server: version 8.1.0, TIBCO JasperReports Server - Community Edition: versions 8.1.0 and below, TIBCO JasperReports Server - Developer Edition: versions 8.1.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 8.0.2 and below, TIBCO JasperReports Server for AWS Marketplace: version 8.1.0, TIBCO JasperReports Server for Microsoft Azure: versions 8.0.2 and below, and TIBCO JasperReports Server for Microsoft Azure: version 8.1.0.

CVE-2022-41561CRITICAL 9.1

The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows a privileged/administrative attacker with network access to execute Remote Code Execution to obtain a reverse shell on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 8.0.2 and below, TIBCO JasperReports Server: version 8.1.0, TIBCO JasperReports Server - Community Edition: versions 8.1.0 and below, TIBCO JasperReports Server - Developer Edition: versions 8.1.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 8.0.2 and below, TIBCO JasperReports Server for AWS Marketplace: version 8.1.0, TIBCO JasperReports Server for Microsoft Azure: versions 8.0.2 and below, and TIBCO JasperReports Server for Microsoft Azure: version 8.1.0.

CVE-2022-41560MEDIUM 6.5

The Statement Set Upload via the Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Denial of Service Attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: version 10.5.0.

CVE-2022-41559CRITICAL 9.3

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: version 10.5.0.

CVE-2022-41558CRITICAL 9.0

The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 11.4.4 and below, TIBCO Spotfire Analyst: versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, and 12.0.1, TIBCO Spotfire Analyst: version 12.1.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 12.1.0 and below, TIBCO Spotfire Desktop: versions 11.4.4 and below, TIBCO Spotfire Desktop: versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, and 12.0.1, TIBCO Spotfire Desktop: version 12.1.0, TIBCO Spotfire Server: versions 11.4.8 and below, TIBCO Spotfire Server: versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, and 12.0.1, and TIBCO Spotfire Server: version 12.1.0.

CVE-2022-30578HIGH 8.0

The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.4.1 and below.

CVE-2022-30577HIGH 8.0

The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8.

tibco — Vendor | Dragons Community