Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Vios CRITICAL 9.8
CVE-2026-16913

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16917

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Aix CRITICAL 9.8
CVE-2026-16919

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied …

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16894

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.6
CVE-2026-16903

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-b…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16882

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special e…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16885

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16872

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.9
CVE-2026-16816

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralizatio…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16656

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.9
CVE-2026-15068

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutraliz…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.1
CVE-2026-15065

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate c…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Db2 Mirror For I CRITICAL 9.8
CVE-2026-17184

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

Fix: after 7.6
Fix from $5,750 2026-08-14
Db2 Mirror For I CRITICAL 9.8
CVE-2026-17186

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme…

Fix: after 7.6
Fix from $5,750 2026-08-14
Db2 Mirror For I CRITICAL 9.8
CVE-2026-17182

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp…

Fix: after 7.6
Fix from $5,750 2026-08-14
I CRITICAL 10.0
CVE-2026-18193

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.9
CVE-2026-18249

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from…

No fix yet
Fix from $5,750 2026-08-13
Documentation Offline CRITICAL 9.8
CVE-2026-17481

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.

Fix: 1.5.1+
Fix from $5,750 2026-08-13
Documentation Offline CRITICAL 9.8
CVE-2026-17482

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

Fix: 1.5.1+
Fix from $5,750 2026-08-13
I CRITICAL 9.6
CVE-2026-17101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-17206

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Fix: after 7.6
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-16961

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.1
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b…

No fix yet
Fix from $5,750 2026-08-13
Websphere Application Server CRITICAL 9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…

Fix: 26.0.0.9+
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

No fix yet
Fix from $2,300 2026-08-13
Db2 CRITICAL 9.8
CVE-2026-10534

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

Fix: after 12.1.5
Fix from $2,300 2026-08-12
Security Verify Access CRITICAL 9.8
CVE-2026-17616

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: 10.0.9.2 / 11.0.3+
Fix from $2,300 2026-08-12
I Access Client Solutions CRITICAL 9.6
CVE-2026-13433

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an I…

Fix: 1.1.9.14+
Fix from $2,300 2026-08-12
Db2 CRITICAL 9.8
CVE-2026-10543

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.

Fix: after 12.1.5
Fix from $2,300 2026-08-12