Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I HIGH 7.5
CVE-2026-16982

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.8
CVE-2026-16975

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-16967

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time…

No fix yet
Fix from $4,900 2026-08-13
I CRITICAL 9.8
CVE-2026-16961

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …

No fix yet
Fix from $5,750 2026-08-13
I MEDIUM 6.5
CVE-2026-16929

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow.

No fix yet
Fix from $4,000 2026-08-13
I HIGH 8.8
CVE-2026-16908

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul…

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.8
CVE-2026-16898

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an a…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-16896

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TO…

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-16887

IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

No fix yet
Fix from $4,900 2026-08-13
I MEDIUM 6.5
CVE-2026-16878

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
I HIGH 7.5
CVE-2026-16868

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length pr…

No fix yet
Fix from $4,900 2026-08-13
I CRITICAL 9.8
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…

No fix yet
Fix from $5,750 2026-08-13
I MEDIUM 5.3
CVE-2026-16861

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 5.3
CVE-2026-16859

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
I HIGH 7.5
CVE-2026-16853

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

No fix yet
Fix from $4,900 2026-08-13
I CRITICAL 9.1
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b…

No fix yet
Fix from $5,750 2026-08-13
I HIGH 8.8
CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
I MEDIUM 6.5
CVE-2026-16692

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

No fix yet
Fix from $4,000 2026-08-13
I HIGH 8.8
CVE-2026-16674

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-73652

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73037

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.6
CVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation th…

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.8
CVE-2026-18071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.2
CVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I CRITICAL 9.8
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.1
CVE-2026-72741

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.8
CVE-2026-18428

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2024-58374

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attacke…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2019-25765

ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL b…

No fix yet
Fix from $4,900 2026-08-13