Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16892 | MEDIUM | 5.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching. | |
| CVE-2026-16941 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization. | |
| CVE-2026-16966 | MEDIUM | Patched | 5.3 | 2026-09-02 | The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to rea… |
| CVE-2026-16983 | MEDIUM | Patched | 4.3 | 2026-09-02 | The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protec… |
| CVE-2026-17057 | MEDIUM | 6.5 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions. | |
| CVE-2026-17207 | MEDIUM | 6.5 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow. | |
| CVE-2026-17255 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements. | |
| CVE-2026-17259 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. | |
| CVE-2026-17270 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. | |
| CVE-2026-17273 | MEDIUM | 6.5 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. | |
| CVE-2026-17274 | MEDIUM | 5.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds. | |
| CVE-2026-17440 | MEDIUM | 5.5 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke… | |
| CVE-2026-17442 | MEDIUM | 5.1 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke… | |
| CVE-2026-17443 | MEDIUM | 5.3 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authen… | |
| CVE-2026-17444 | MEDIUM | 5.3 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authen… | |
| CVE-2026-17469 | MEDIUM | 5.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser. | |
| CVE-2026-17470 | MEDIUM | 5.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. | |
| CVE-2026-17483 | MEDIUM | 4.3 | 2026-09-04 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. | |
| CVE-2026-17499 | MEDIUM | 4.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| CVE-2026-17509 | MEDIUM | 6.5 | 2026-09-08 | The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to i… | |
| CVE-2026-17517 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attac… |
| CVE-2026-17539 | MEDIUM | 5.9 | 2026-09-03 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhance… | |
| CVE-2026-17563 | MEDIUM | Patched | 5.3 | 2026-09-02 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the f… |
| CVE-2026-17589 | MEDIUM | 4.9 | 2026-09-01 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.… | |
| CVE-2026-17621 | MEDIUM | 5.4 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing… |