Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
HIGH 7.8
CVE-2026-16703
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 7.5
CVE-2026-16690
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.2
CVE-2026-16686
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication.
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.8
CVE-2026-16656
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
Vios
4.1.0.50 / 4.1.1.30+
MEDIUM 6.0
CVE-2026-15961
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sen…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 8.1
CVE-2026-15078
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation…
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.9
CVE-2026-15068
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutraliz…
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.1
CVE-2026-15065
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate c…
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.2
CVE-2026-15061
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 7.5
CVE-2026-14970
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 7.1
CVE-2026-76245
stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid pe…
No fix yet
CRITICAL 9.1
CVE-2026-76244
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection whe…
No fix yet
CRITICAL 9.2
CVE-2026-76243
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read,…
No fix yet
CRITICAL 9.1
CVE-2026-76242
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval …
No fix yet
HIGH 7.3
CVE-2026-76241
stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If …
No fix yet
HIGH 7.5
CVE-2026-76240
stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schem…
No fix yet
MEDIUM 6.3
CVE-2026-76239
Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify…
No fix yet
HIGH 7.2
CVE-2026-76238
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated atta…
No fix yet
HIGH 8.6
CVE-2026-76237
stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On mu…
No fix yet
HIGH 7.2
CVE-2026-76236
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mech…
No fix yet
HIGH 7.5
CVE-2026-76234
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly…
No fix yet
MEDIUM 6.7
CVE-2026-76233
Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended …
Patch available
MEDIUM 6.7
CVE-2026-76232
Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appen…
Patch available
MEDIUM 6.7
CVE-2026-76231
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names a…
Patch available
MEDIUM 6.7
CVE-2026-76230
Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are…
Patch available
MEDIUM 6.7
CVE-2026-76229
Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided char…
Patch available
MEDIUM 6.7
CVE-2026-76228
Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle …
No fix yet
MEDIUM 5.5
CVE-2026-76227
Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renova…
No fix yet
MEDIUM 6.3
CVE-2026-76226
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFi…
No fix yet
HIGH 7.7
CVE-2026-76225
ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTT…
No fix yet