Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

I MEDIUM 6.3
CVE-2026-17420

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el…

Fix: after 7.6
Fix from $4,000 2026-08-12
I MEDIUM 6.5
CVE-2026-17419

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used…

Fix: after 7.6
Fix from $4,000 2026-08-12
I HIGH 7.8
CVE-2026-17418

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elemen…

Fix: after 7.6
Fix from $4,900 2026-08-12
I CRITICAL 9.9
CVE-2026-17276

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 7.5
CVE-2026-17271

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.

Fix: after 7.6
Fix from $4,900 2026-08-12
I MEDIUM 6.8
CVE-2026-17268

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session toke…

Fix: after 7.6
Fix from $4,000 2026-08-12
I MEDIUM 6.5
CVE-2026-17266

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to …

Fix: after 7.6
Fix from $4,000 2026-08-12
I MEDIUM 6.5
CVE-2026-17248

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme…

Fix: after 7.6
Fix from $4,000 2026-08-12
I CRITICAL 9.8
CVE-2026-17218

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-17110

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improp…

Fix: after 7.6
Fix from $4,900 2026-08-12
Db2 Mirror For I CRITICAL 9.8
CVE-2026-16956

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 7.5
CVE-2026-16931

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.

Fix: after 7.6
Fix from $4,900 2026-08-12
I HIGH 7.6
CVE-2026-16907

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

Fix: after 7.6
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-16906

IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.1
CVE-2026-16904

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo…

Fix: after 7.6
Fix from $4,900 2026-08-12
I HIGH 7.7
CVE-2026-16863

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

Fix: after 7.6
Fix from $4,900 2026-08-12
I CRITICAL 9.9
CVE-2026-16860

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-16856

IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

No fix yet
Fix from $4,900 2026-08-12
GitLab CRITICAL 9.0
CVE-2026-16627

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an aut…

Fix: 19.2.2+
Fix from $5,750 2026-08-12
GitLab HIGH 8.5
CVE-2026-15423

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

Fix: 19.0.6 / 19.1.4+
Fix from $4,900 2026-08-12
Allura CRITICAL 9.8
CVE-2026-73240

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme…

Fix: 1.19.1+
Fix from $5,750 2026-08-12
Allura MEDIUM 6.5
CVE-2026-73239

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All…

Fix: 1.19.1+
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.9
CVE-2026-73297

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security…

Patch available
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.4
CVE-2026-73296

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and…

Patch available
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-73295

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/temp…

Patch available
Fix from $4,000 2026-08-12
Allura MEDIUM 6.1
CVE-2026-73238

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.…

Fix: 1.19.1+
Fix from $4,000 2026-08-12
Allura MEDIUM 6.1
CVE-2026-73237

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgr…

Fix: 1.19.1+
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-48554

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macr…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-48553

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thr…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-48552

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string value…

No fix yet
Fix from $4,000 2026-08-12