Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2026-17420 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el… I after 7.6 Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-17419 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used… I after 7.6 Fix from $4,0002026-08-12 HIGH 7.8 CVE-2026-17418 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elemen… I after 7.6 Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-17276 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high… I after 7.6 Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-17271 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. I after 7.6 Fix from $4,9002026-08-12 MEDIUM 6.8 CVE-2026-17268 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session toke… I after 7.6 Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-17266 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to … I after 7.6 Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-17248 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme… I after 7.6 Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-17218 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. I after 7.6 Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-17110 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improp… I after 7.6 Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-16956 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements… Db2 Mirror For I after 7.6 Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-16931 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options. I after 7.6 Fix from $4,9002026-08-12 HIGH 7.6 CVE-2026-16907 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking. I after 7.6 Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-16906 IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization … I No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-16904 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo… I after 7.6 Fix from $4,9002026-08-12 HIGH 7.7 CVE-2026-16863 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. I after 7.6 Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-16860 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element. I after 7.6 Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-16856 IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command. I No fix yet Fix from $4,9002026-08-12 CRITICAL 9.0 CVE-2026-16627 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an aut… GitLab 19.2.2+ Fix from $5,7502026-08-12 HIGH 8.5 CVE-2026-15423 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under … GitLab 19.0.6 / 19.1.4+ Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-73240 Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme… Allura 1.19.1+ Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-73239 Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All… Allura 1.19.1+ Fix from $4,0002026-08-12 MEDIUM 6.9 CVE-2026-73297 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security… Patch available Fix from $4,0002026-08-12 CRITICAL 9.4 CVE-2026-73296 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and… Patch available Fix from $5,7502026-08-12 MEDIUM 5.4 CVE-2026-73295 Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/temp… Patch available Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-73238 XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.… Allura 1.19.1+ Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-73237 XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgr… Allura 1.19.1+ Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-48554 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macr… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-48553 Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thr… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-48552 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string value… No fix yet Fix from $4,0002026-08-12