Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-17483 | MEDIUM | 4.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access … | Sep 04, 2026 |
| CVE-2026-17470 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. | Sep 04, 2026 |
| CVE-2026-17469 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in … | Sep 04, 2026 |
| CVE-2026-17444 | MEDIUM | 5.3 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated … | Sep 04, 2026 |
| CVE-2026-17443 | MEDIUM | 5.3 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated … | Sep 04, 2026 |
| CVE-2026-17442 | MEDIUM | 5.1 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker … | Sep 04, 2026 |
| CVE-2026-17440 | MEDIUM | 5.5 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker … | Sep 04, 2026 |
| CVE-2026-17274 | MEDIUM | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds. | Sep 04, 2026 |
| CVE-2026-17273 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. | Sep 04, 2026 |
| CVE-2026-17270 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. | Sep 04, 2026 |
| CVE-2026-17259 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. | Sep 04, 2026 |
| CVE-2026-17255 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix … | Sep 04, 2026 |
| CVE-2026-17207 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer … | Sep 04, 2026 |
| CVE-2026-17057 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing … | Sep 04, 2026 |
| CVE-2026-16941 | MEDIUM | 4.3 | IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization. | Sep 04, 2026 |
| CVE-2026-16892 | MEDIUM | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching. | Sep 04, 2026 |
| CVE-2026-16826 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in … | Sep 04, 2026 |
| CVE-2026-16693 | MEDIUM | 4.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants … | Sep 04, 2026 |
| CVE-2026-16689 | MEDIUM | 6.2 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker … | Sep 04, 2026 |
| CVE-2026-16660 | MEDIUM | 5.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. | Sep 04, 2026 |
| CVE-2026-16180 | MEDIUM | 5.7 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated … | Sep 04, 2026 |
| CVE-2026-14470 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL … | Sep 04, 2026 |
| CVE-2026-14350 | MEDIUM | 5.3 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper … | Sep 04, 2026 |
| CVE-2026-13297 | UNKNOWN | — | IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | Sep 04, 2026 |
| CVE-2026-85730 | UNKNOWN | — | smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an … | Sep 04, 2026 |