CVE Feed

    Dashboard / CVE

    4.5
    Medium

    CVE-2026-18086

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

    Published: 13 Aug 2026
    7.5
    High

    CVE-2026-18077

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.

    Published: 13 Aug 2026
    4.3
    Medium

    CVE-2026-18068

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-18020

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17649

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

    Published: 13 Aug 2026
    8.6
    High

    CVE-2026-17502

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

    Published: 13 Aug 2026
    9.8
    Critical

    CVE-2026-17482

    Last Modified: 17 Aug 2026

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

    Published: 13 Aug 2026
    8.8
    High

    CVE-2026-17481

    Last Modified: 17 Aug 2026

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.

    Published: 13 Aug 2026
    4.8
    Medium

    CVE-2026-17476

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.

    Published: 13 Aug 2026
    7.5
    High

    CVE-2026-17473

    Last Modified: 25 Aug 2026

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory.

    Published: 13 Aug 2026
    4.4
    Medium

    CVE-2026-17438

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17468

    Last Modified: 25 Aug 2026

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key.

    Published: 13 Aug 2026
    6.5
    Medium

    CVE-2026-17075

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.

    Published: 13 Aug 2026
    8.2
    High

    CVE-2026-17272

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

    Published: 13 Aug 2026
    5.4
    Medium

    CVE-2026-17226

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17216

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17212

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

    Published: 13 Aug 2026
    9.6
    Critical

    CVE-2026-8715

    Last Modified: 28 Aug 2026

    Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

    Published: 13 Aug 2026
    8.3
    High

    CVE-2026-17101

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

    Published: 13 Aug 2026
    7.3
    High

    CVE-2026-17099

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.

    Published: 13 Aug 2026
    4.3
    Medium

    CVE-2026-17088

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17078

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17077

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-17076

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.

    Published: 13 Aug 2026
    3.1
    Low

    CVE-2026-17074

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management.

    Published: 13 Aug 2026
    2.7
    Low

    CVE-2026-17071

    Last Modified: 19 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.

    Published: 13 Aug 2026
    2.9
    Low

    CVE-2026-19748

    Last Modified: 14 Aug 2026

    A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.

    Published: 13 Aug 2026
    9.9
    Critical

    CVE-2026-73656

    Last Modified: 14 Aug 2026

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to the victim deployment, and move the victim deployment from BUILDING to DEPLOYING. This issue is fixed in version 4.5.6.

    Published: 13 Aug 2026
    8.1
    High

    CVE-2026-17069

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.

    Published: 13 Aug 2026
    8.1
    High

    CVE-2026-17045

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.

    Published: 13 Aug 2026
    3.8
    Low

    CVE-2026-17043

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

    Published: 13 Aug 2026
    8.8
    High

    CVE-2026-17029

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

    Published: 13 Aug 2026
    8.8
    High

    CVE-2026-16987

    Last Modified: 14 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.

    Published: 13 Aug 2026
    8.8
    High

    CVE-2026-16975

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.

    Published: 13 Aug 2026
    7.4
    High

    CVE-2026-73655

    Last Modified: 18 Aug 2026

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified assertion. When existingEmailUser && !existingUser is true, the flow writes the new Google authIdentifier into the existing email-matched account and returns that user object, allowing an attacker-controlled Google profile with an unverified matching email to take over the account. This issue is fixed in version 4.5.2.

    Published: 13 Aug 2026
    8.5
    High

    CVE-2026-16967

    Last Modified: 14 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.

    Published: 13 Aug 2026
    7.6
    High

    CVE-2026-16961

    Last Modified: 13 Aug 2026

    IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

    Published: 13 Aug 2026
    8.5
    High

    CVE-2026-16908

    Last Modified: 14 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.

    Published: 13 Aug 2026
    7.8
    High

    CVE-2026-16898

    Last Modified: 14 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.

    Published: 13 Aug 2026
    7.1
    High

    CVE-2026-16896

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.

    Published: 13 Aug 2026
    7.5
    High

    CVE-2026-16887

    Last Modified: 17 Aug 2026

    IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

    Published: 13 Aug 2026
    5.4
    Medium

    CVE-2026-16878

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

    Published: 13 Aug 2026
    4.3
    Medium

    CVE-2026-16871

    Last Modified: 13 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow.

    Published: 13 Aug 2026
    8.1
    High

    CVE-2026-16868

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.

    Published: 13 Aug 2026
    8.1
    High

    CVE-2026-16867

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-16861

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

    Published: 13 Aug 2026
    5.3
    Medium

    CVE-2026-16859

    Last Modified: 13 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

    Published: 13 Aug 2026
    8.9
    High

    CVE-2026-19747

    Last Modified: 14 Aug 2026

    A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.

    Published: 13 Aug 2026
    6.5
    Medium

    CVE-2026-16853

    Last Modified: 17 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

    Published: 13 Aug 2026
    8.6
    High

    CVE-2026-16815

    Last Modified: 14 Aug 2026

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.

    Published: 13 Aug 2026