Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-63722

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands b…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 8.7
CVE-2026-63188

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.3
CVE-2026-63187

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directl…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.5
CVE-2026-62317

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/sr…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-61711

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom fron…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-55090

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtm…

Patch available
Fix from $4,000 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-55089

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in th…

Patch available
Fix from $5,750 2026-08-19
Unclassified MEDIUM 6.8
CVE-2026-55088

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to …

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.1
CVE-2026-55087

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/h…

Patch available
Fix from $4,000 2026-08-19
Unclassified CRITICAL 9.6
CVE-2026-55085

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a num…

Patch available
Fix from $5,750 2026-08-19
Unclassified MEDIUM 5.1
CVE-2026-54742

Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature…

Patch available
Fix from $4,000 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive informat…

No fix yet
Fix from $5,750 2026-08-19
Power System S1122 \(9824 22a\) Firmware HIGH 7.3
CVE-2026-18871

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware config…

No fix yet
Fix from $4,900 2026-08-19
Power System S1122 \(9824 22a\) Firmware HIGH 8.8
CVE-2026-18821

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is a…

No fix yet
Fix from $4,900 2026-08-19
Power System S1122 \(9824 22a\) Firmware HIGH 8.8
CVE-2026-17414

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is a…

No fix yet
Fix from $4,900 2026-08-19
Power System S1122 \(9824 22a\) Firmware MEDIUM 6.7
CVE-2026-17097

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerabil…

No fix yet
Fix from $4,000 2026-08-19
Power System S1122 \(9824 22a\) Firmware HIGH 8.4
CVE-2026-17091

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerabil…

No fix yet
Fix from $4,900 2026-08-19
Power System S1122 \(9824 22a\) Firmware HIGH 7.9
CVE-2026-17063

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface be…

No fix yet
Fix from $4,900 2026-08-19
Power System S922 \(9009 22g\) Firmware HIGH 7.3
CVE-2026-17042

IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulner…

No fix yet
Fix from $4,900 2026-08-19
Power System S1122 \(9824 22a\) Firmware MEDIUM 6.5
CVE-2026-17028

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerabil…

No fix yet
Fix from $4,000 2026-08-19
Power System S1122 \(9824 22a\) Firmware HIGH 8.2
CVE-2026-16933

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 …

No fix yet
Fix from $4,900 2026-08-19
Aix CRITICAL 9.8
CVE-2026-16919

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied …

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16917

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios MEDIUM 6.7
CVE-2026-16914

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,000 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16913

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios HIGH 8.8
CVE-2026-16911

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Vios HIGH 8.8
CVE-2026-16909

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Vios CRITICAL 9.6
CVE-2026-16903

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-b…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios HIGH 8.8
CVE-2026-16901

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16894

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19