Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18526 | UNKNOWN | — | HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | Aug 19, 2026 |
| CVE-2026-16818 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource … | Aug 19, 2026 |
| CVE-2026-16817 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL … | Aug 19, 2026 |
| CVE-2026-16816 | CRITICAL | 9.9 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of … | Aug 19, 2026 |
| CVE-2026-16814 | HIGH | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. | Aug 19, 2026 |
| CVE-2026-16706 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds … | Aug 19, 2026 |
| CVE-2026-16703 | HIGH | 7.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | Aug 19, 2026 |
| CVE-2026-16690 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource … | Aug 19, 2026 |
| CVE-2026-16686 | HIGH | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication. | Aug 19, 2026 |
| CVE-2026-16656 | CRITICAL | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication. | Aug 19, 2026 |
| CVE-2026-15961 | MEDIUM | 5.2 | IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sensitive information or cause a … | Aug 19, 2026 |
| CVE-2026-15078 | HIGH | 8.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to … | Aug 19, 2026 |
| CVE-2026-15068 | CRITICAL | 9.9 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization … | Aug 19, 2026 |
| CVE-2026-15065 | CRITICAL | 9.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of … | Aug 19, 2026 |
| CVE-2026-15061 | HIGH | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path … | Aug 19, 2026 |
| CVE-2026-14970 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow. | Aug 19, 2026 |
| CVE-2026-76245 | UNKNOWN | — | stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as … | Aug 19, 2026 |
| CVE-2026-76244 | UNKNOWN | — | stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly … | Aug 19, 2026 |
| CVE-2026-76243 | UNKNOWN | — | stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity … | Aug 19, 2026 |
| CVE-2026-76242 | UNKNOWN | — | stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration … | Aug 19, 2026 |
| CVE-2026-76241 | UNKNOWN | — | stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into … | Aug 19, 2026 |
| CVE-2026-76240 | UNKNOWN | — | stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the … | Aug 19, 2026 |
| CVE-2026-76239 | MEDIUM | 6.3 | Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers … | Aug 19, 2026 |
| CVE-2026-76238 | UNKNOWN | — | stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one … | Aug 19, 2026 |
| CVE-2026-76237 | UNKNOWN | — | stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the … | Aug 19, 2026 |