CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2026-76827

    Last Modified: 27 Aug 2026

    A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.

    Published: 19 Aug 2026
    2.3
    Low

    CVE-2026-61712

    Last Modified: 21 Aug 2026

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1.

    Published: 19 Aug 2026
    5.5
    Medium

    CVE-2026-76574

    Last Modified: 25 Aug 2026

    A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16919

    Last Modified: 27 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16917

    Last Modified: 21 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.

    Published: 19 Aug 2026
    6.7
    Medium

    CVE-2026-16914

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16913

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16911

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16909

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.

    Published: 19 Aug 2026
    9.6
    Critical

    CVE-2026-16903

    Last Modified: 21 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16901

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

    Published: 19 Aug 2026
    4.4
    Medium

    CVE-2026-16897

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16894

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 19 Aug 2026
    3.3
    Low

    CVE-2026-16891

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

    Published: 19 Aug 2026
    3.6
    Low

    CVE-2026-16890

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.

    Published: 19 Aug 2026
    4.3
    Medium

    CVE-2026-16886

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

    Published: 19 Aug 2026
    3.7
    Low

    CVE-2026-16888

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16885

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 19 Aug 2026
    6.3
    Medium

    CVE-2026-63187

    Last Modified: 25 Aug 2026

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title to npx commitlint. A pull request title containing a single quote could terminate the echo string and append arbitrary shell commands on the GitHub Actions runner. The pull_request trigger used a read-only GITHUB_TOKEN and did not expose repository secrets, but injected commands could alter or disrupt the ephemeral workflow execution. This issue is fixed in version 1.41.0.

    Published: 19 Aug 2026
    6.5
    Medium

    CVE-2026-17028

    Last Modified: 25 Aug 2026

    IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.

    Published: 19 Aug 2026
    8.7
    High

    CVE-2026-63188

    Last Modified: 21 Aug 2026

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static asset requests through packages/tunnel/src/commands/tunnel/utils.ts using path.join(staticPath, request.url) and then fs.open(requestPath, "r") without URL normalization or a containment check. When --experience-path was enabled and the tunnel port was reachable, an unauthenticated requester could send a path containing ../ to createStaticFileProxy and read files outside the configured static directory that were readable by the logto-tunnel process. The service used server.listen(port), which could expose the tunnel to other hosts depending on the platform and deployment. This issue is fixed in version 0.3.9.

    Published: 19 Aug 2026
    8.4
    High

    CVE-2026-17091

    Last Modified: 25 Aug 2026

    IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system.

    Published: 19 Aug 2026
    5.5
    Medium

    CVE-2026-16883

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16882

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

    Published: 19 Aug 2026
    7.3
    High

    CVE-2026-17097

    Last Modified: 25 Aug 2026

    IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16877

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 19 Aug 2026
    7.8
    High

    CVE-2026-16875

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.

    Published: 19 Aug 2026
    7.8
    High

    CVE-2026-16874

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges due to improper enforcement of RBAC authentication roles.

    Published: 19 Aug 2026
    7.8
    High

    CVE-2026-16873

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privilege escalation due to an out-of-bounds write.

    Published: 19 Aug 2026
    7.5
    High

    CVE-2026-18821

    Last Modified: 25 Aug 2026

    IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

    Published: 19 Aug 2026
    7.5
    High

    CVE-2026-62317

    Last Modified: 21 Aug 2026

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain from email input to construct subaddressingRegex when blockSubaddressing was enabled. The permissive emailRegEx accepted multiple at signs and regular expression metacharacters, and POST /api/experience/verification/verification-code could therefore cause catastrophic backtracking in subaddressingRegex.test(email). The resulting event-loop stall could make authentication, token issuance, SSO, and the administrative console unavailable. This issue is fixed in version 1.41.0.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16872

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 19 Aug 2026
    7.8
    High

    CVE-2026-16869

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.

    Published: 19 Aug 2026
    4.5
    Medium

    CVE-2026-16724

    Last Modified: 25 Aug 2026

    IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through FW1060.80 is affected by a vulnerability in the Virtualization Management Interface (VMI). An attacker with authenticated administrator-level access can cause the VMI to crash. The VMI will restart automatically; however, repeated exploitation could result in a sustained availability impact.

    Published: 19 Aug 2026
    4.8
    Medium

    CVE-2026-16866

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16865

    Last Modified: 20 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16864

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-16862

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 19 Aug 2026
    8.2
    High

    CVE-2026-16857

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication.

    Published: 19 Aug 2026
    8
    High

    CVE-2026-76139

    Last Modified: 27 Aug 2026

    A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.

    Published: 19 Aug 2026
    5.5
    Medium

    CVE-2026-16855

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap buffer overflow.

    Published: 19 Aug 2026
    7.7
    High

    CVE-2026-75569

    Last Modified: 2 Sept 2026

    A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.

    Published: 19 Aug 2026
    7.5
    High

    CVE-2026-16852

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.

    Published: 19 Aug 2026
    7.4
    High

    CVE-2026-16851

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a use-after-free.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16850

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.

    Published: 19 Aug 2026
    4.3
    Medium

    CVE-2026-16849

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper check for an array index boundary.

    Published: 19 Aug 2026
    7.3
    High

    CVE-2026-18871

    Last Modified: 25 Aug 2026

    IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing. An attacker with authenticated service-level access to the service processor can write specially crafted configuration data, causing the host firmware boot stack to crash with possible memory corruption during system initialisation, resulting in an integrity and availability impact to the managed system.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16848

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.

    Published: 19 Aug 2026
    4.2
    Medium

    CVE-2026-55086

    Last Modified: 25 Aug 2026

    Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared world-writable temporary directory, a local unprivileged attacker who predicts a filename can precreate a symbolic link to a file writable by the Etherpad process. Subsequent import or export operations can follow the link through fs.writeFile, fs.rename, or document-conversion output and overwrite the target with partially attacker-controlled content. This issue is fixed in version 3.1.0.

    Published: 19 Aug 2026
    9.6
    Critical

    CVE-2026-55085

    Last Modified: 21 Aug 2026

    Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, including list:number1 and a malicious start value. Any user with write access to a pad can store markup that executes as cross-site scripting when another user opens the pad or /timeslider, including when an administrator views the pad. This issue is fixed in version 3.3.1.

    Published: 19 Aug 2026