Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-16982 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow. I No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-16975 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. I No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-16967 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time… I No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-16961 IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker … I No fix yet Fix from $5,7502026-08-13 MEDIUM 6.5 CVE-2026-16929 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow. I No fix yet Fix from $4,0002026-08-13 HIGH 8.8 CVE-2026-16908 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul… I No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-16898 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an a… I No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-16896 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TO… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-16887 IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. I No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-16878 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-16868 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length pr… I No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-16867 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au… I No fix yet Fix from $5,7502026-08-13 MEDIUM 5.3 CVE-2026-16861 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-16859 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-16853 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-16815 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b… I No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-16722 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management. I No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-16692 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. I No fix yet Fix from $4,0002026-08-13 HIGH 8.8 CVE-2026-16674 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path. I No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-73652 vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.1 CVE-2026-73037 Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without … No fix yet Fix from $4,0002026-08-13 HIGH 8.6 CVE-2026-72777 Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation th… No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-18071 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. I No fix yet Fix from $4,9002026-08-13 HIGH 8.2 CVE-2026-17220 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. I No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-17197 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. I No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-72741 Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-67614 CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta… No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-18428 A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query … No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2024-58374 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attacke… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2019-25765 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL b… No fix yet Fix from $4,9002026-08-13