LIVE FEED
225 events · 4 sources · newest first
Events in view
225
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-08-20
NVD CVE
CVE-2026-17423: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.
2026-08-20
NVD CVE
CVE-2026-17000: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.
2026-08-20
NVD CVE
CVE-2026-17060: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.
2026-08-20
NVD CVE
CVE-2026-18670: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
2026-08-20
NVD CVE
CVE-2026-17003: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.
2026-08-20
NVD CVE
CVE-2026-17024: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.
2026-08-20
NVD CVE
CVE-2026-18716: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
2026-08-20
NVD CVE
CVE-2026-17436: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
2026-08-20
NVD CVE
CVE-2026-17138: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
2026-08-20
NVD CVE
CVE-2026-18832: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
2026-08-20
NVD CVE
CVE-2026-17006: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
2026-08-13
NVD CVE
CVE-2026-17481: IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e
HIGH
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.
arbitrary-code-executioncve-2026-17481documentationibmimproper-outputs-neutralizationlognvd-cveoffline
2026-08-13
NVD CVE
CVE-2026-16867: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
authenticate-userauthenticationcve-2026-16867ibm-iimproper-authenticationntlm-session-negotiationnvd-cveremote-attackers
2026-08-13
NVD CVE
CVE-2026-16961: IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could s
HIGH
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cvecve-2026-16961data-deletiondata-modificationdatabaseibmibm-iinformation-disclosure
2026-08-13
NVD CVE
CVE-2026-18249: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
2026-08-13
NVD CVE
CVE-2026-17101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
2026-08-13
NVD CVE
CVE-2026-18193: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
2026-08-13
NVD CVE
CVE-2026-17206: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
arbitrary-code-executionbuffer-overflowcve-2026-17206ibmibm-invd-cveoperating-systemsremote-code-execution
2026-08-13
NVD CVE
CVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
cve-2026-16815denialibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6nvd-cve
2026-08-13
NVD CVE
CVE-2026-17197: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
client-asserted-identitycve-2026-17197ibmibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6
2026-08-12
NVD CVE
CVE-2026-17111: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker co
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cve-2026-17111data-deletiondata-modificationdatabaseibmibm-iibm-i-7-3ibm-i-7-4
2026-08-12
NVD CVE
CVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to do
HIGH
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised...
2026-08-12
NVD CVE
CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
HIGH
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate...
2026-08-12
NVD CVE
CVE-2026-10543: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privil
HIGH
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
2026-08-12
NVD CVE
CVE-2026-10534: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer
HIGH
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
buffer-overflowcve-2026-10534databasedb2ibmixf-import-parsernvd-cvesecurity
2026-08-12
NVD CVE
CVE-2026-18847: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to ha
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
credential-harvestingcve-2026-18847iibmibm-inavigatornvd-cveremote-attacks
2026-08-11
NVD CVE
CVE-2026-65768: Improper limitation of a pathname to a restricted directory ('path traversal') i
HIGH
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
androidandroid-appscode-executioncve-2026-65768exploitmicrosoftmicrosoft-teamnetwork-security
2026-08-11
NVD CVE
CVE-2026-57104: Improper neutralization of input during web page generation ('cross-site scripti
HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
2026-08-10
NVD CVE
CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
HIGH
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...
2026-08-07
NVD CVE
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks
2026-08-07
NVD CVE
CVE-2026-56793: Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
HIGH
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,...
cve-2026-56793cybersecuritydelldfar-252-204-7012improper-authenticationincident-responsenist-800-171nvd-cve
2026-08-05
NVD CVE
CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-servi
HIGH
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata...
authenticationcve-2026-16443forgeryidentity-brokeridentity-providerkeycloakmetadata-importnvd-cve
2026-08-05
NVD CVE
CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
HIGH
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event...
authenticationcve-2026-10025event-processingibminjectioninterim-fixesnvd-cveport-514
2026-08-05
NVD CVE
CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
HIGH
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
applications-gateways-operatorscustom-resourcecve-2026-17617ibmnvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-05
NVD CVE
CVE-2026-16442: A flaw was found in the SAML broker component of Keycloak, which is used to mana
HIGH
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a...
access-controlaccounts-linkingauthenticationcve-2026-16442identity-federationidentity-managementkeycloaklogins-restrictions
2026-08-05
NVD CVE
CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t
HIGH
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
cryptographiccve-2026-9205ibmkey-derivationlangflownvd-cvevulnerabilityweak-key
2026-08-05
NVD CVE
CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server...
application-serverarbitrary-code-executionclass-loadingcve-2026-8400ibmibm-sdkiiopjava
2026-08-05
NVD CVE
CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
HIGH
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under...
api-keyauthentication-tokencve-2026-8470deterministic-rngencryption-keysfernet-encryptionsibm-langflownvd-cve
2026-08-04
NVD CVE
CVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge
HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
chromiumcve-2026-66321cybersecuritydefense-industrial-basedfar-252-204-7012information-securitymicrosoftmicrosoft-edge
2026-07-30
NVD CVE
CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
HIGH
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
arbitrary-commandscrlf-character-neutralizationscve-2026-14522ibm-apps-connect-enterprisenvd-cveremote-attacksvulnerability