Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47882
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16861 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. | Aug 13, 2026 |
| CVE-2026-16859 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. | Aug 13, 2026 |
| CVE-2026-16853 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. | Aug 13, 2026 |
| CVE-2026-16815 | HIGH | 8.6 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to … | Aug 13, 2026 |
| CVE-2026-16722 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management. | Aug 13, 2026 |
| CVE-2026-16713 | MEDIUM | 4.3 | IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation … | Aug 13, 2026 |
| CVE-2026-16692 | MEDIUM | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. | Aug 13, 2026 |
| CVE-2026-16674 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path. | Aug 13, 2026 |
| CVE-2026-14875 | HIGH | 7.3 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable … | Aug 13, 2026 |
| CVE-2026-14525 | CRITICAL | 9.4 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 … | Aug 13, 2026 |
| CVE-2026-13460 | HIGH | 7.5 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster … | Aug 13, 2026 |
| CVE-2026-13365 | HIGH | 7.1 | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted … | Aug 13, 2026 |
| CVE-2026-10571 | MEDIUM | 5.7 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could … | Aug 13, 2026 |
| CVE-2026-73653 | CRITICAL | 9.4 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, … | Aug 13, 2026 |
| CVE-2026-73652 | UNKNOWN | — | vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm … | Aug 13, 2026 |
| CVE-2026-73651 | MEDIUM | 5.7 | TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 … | Aug 13, 2026 |
| CVE-2026-73650 | HIGH | 8.2 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, … | Aug 13, 2026 |
| CVE-2026-73482 | HIGH | 8.1 | phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that … | Aug 13, 2026 |
| CVE-2026-73481 | MEDIUM | 5.4 | phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET … | Aug 13, 2026 |
| CVE-2026-73038 | MEDIUM | 6.1 | NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious … | Aug 13, 2026 |
| CVE-2026-73037 | MEDIUM | 6.1 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and … | Aug 13, 2026 |
| CVE-2026-72777 | HIGH | 8.6 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns … | Aug 13, 2026 |
| CVE-2026-18071 | HIGH | 7.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. | Aug 13, 2026 |
| CVE-2026-17220 | HIGH | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a … | Aug 13, 2026 |
| CVE-2026-17197 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. | Aug 13, 2026 |