Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47882
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18846 | HIGH | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of … | Aug 13, 2026 |
| CVE-2026-18164 | HIGH | 8.1 | An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain … | Aug 13, 2026 |
| CVE-2026-17229 | HIGH | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop. | Aug 13, 2026 |
| CVE-2026-17223 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. | Aug 13, 2026 |
| CVE-2026-17206 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | Aug 13, 2026 |
| CVE-2026-17199 | HIGH | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation. | Aug 13, 2026 |
| CVE-2026-17069 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens. | Aug 13, 2026 |
| CVE-2026-17045 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session … | Aug 13, 2026 |
| CVE-2026-17043 | LOW | 3.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. | Aug 13, 2026 |
| CVE-2026-17029 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. | Aug 13, 2026 |
| CVE-2026-17004 | HIGH | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop. | Aug 13, 2026 |
| CVE-2026-16987 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable. | Aug 13, 2026 |
| CVE-2026-16982 | HIGH | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow. | Aug 13, 2026 |
| CVE-2026-16975 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. | Aug 13, 2026 |
| CVE-2026-16967 | HIGH | 8.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to … | Aug 13, 2026 |
| CVE-2026-16961 | HIGH | 7.6 | IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker … | Aug 13, 2026 |
| CVE-2026-16929 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow. | Aug 13, 2026 |
| CVE-2026-16908 | HIGH | 8.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal … | Aug 13, 2026 |
| CVE-2026-16898 | HIGH | 7.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of … | Aug 13, 2026 |
| CVE-2026-16896 | HIGH | 7.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) … | Aug 13, 2026 |
| CVE-2026-16887 | HIGH | 7.5 | IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | Aug 13, 2026 |
| CVE-2026-16878 | MEDIUM | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. | Aug 13, 2026 |
| CVE-2026-16871 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow. | Aug 13, 2026 |
| CVE-2026-16868 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory … | Aug 13, 2026 |
| CVE-2026-16867 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to … | Aug 13, 2026 |