Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72670 |
|
Information Disclosure in CVE-2026-72670 (CVE-2026-72670)
vulnerability in CVE-2026-72670 (CVE-2026-72670). Confidential information can be exposed externally.
|
| CVE-2026-72669 |
|
Vulnerability in CVE-2026-72669 (CVE-2026-72669)
vulnerability in CVE-2026-72669 (CVE-2026-72669). Data can be tampered with by attackers.
|
| CVE-2026-72665 |
|
Vulnerability in CVE-2026-72665 (CVE-2026-72665)
vulnerability in CVE-2026-72665 (CVE-2026-72665). Confidential information can be exposed externally.
|
| CVE-2026-72658 |
|
Cross-Site Request Forgery (CSRF) in privilege-escalation (CVE-2026-72658)
vulnerability in privilege-escalation (CVE-2026-72658). Confidential information can be exposed externally.
|
| CVE-2026-72643 |
|
Authorization Flaw in CVE-2026-72643 (CVE-2026-72643)
vulnerability in CVE-2026-72643 (CVE-2026-72643). Confidential information can be exposed externally.
|
| CVE-2026-72642 |
|
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
|
| CVE-2026-72632 |
|
Vulnerability in CVE-2026-72632 (CVE-2026-72632)
vulnerability in CVE-2026-72632 (CVE-2026-72632). Confidential information can be exposed externally.
|
| CVE-2026-72630 |
|
Authorization Flaw in privilege-escalation (CVE-2026-72630)
vulnerability in privilege-escalation (CVE-2026-72630). Confidential information can be exposed externally.
|
| CVE-2026-72629 |
|
Vulnerability in CVE-2026-72629 (CVE-2026-72629)
vulnerability in CVE-2026-72629 (CVE-2026-72629). Confidential information can be exposed externally.
|
| CVE-2026-18846 |
|
Out-of-Bounds Write in dos (CVE-2026-18846)
out-of-bounds write in dos (CVE-2026-18846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18164 |
|
Vulnerability in CVE-2026-18164 (CVE-2026-18164)
vulnerability in CVE-2026-18164 (CVE-2026-18164). Data can be tampered with by attackers.
|
| CVE-2026-17229 |
|
Vulnerability in dos (CVE-2026-17229)
vulnerability in dos (CVE-2026-17229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17223 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-17206 |
|
Out-of-Bounds Write in ibm (CVE-2026-17206)
out-of-bounds write in ibm (CVE-2026-17206). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17199 |
|
Vulnerability in dos (CVE-2026-17199)
vulnerability in dos (CVE-2026-17199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17069 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-17069)
vulnerability in csrf (CVE-2026-17069). Confidential information can be exposed externally.
|
| CVE-2026-17045 |
|
Vulnerability in ibm (CVE-2026-17045)
vulnerability in ibm (CVE-2026-17045). Confidential information can be exposed externally.
|
| CVE-2026-17029 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out...
|
| CVE-2026-17004 |
|
Vulnerability in dos (CVE-2026-17004)
vulnerability in dos (CVE-2026-17004). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16987 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to...
|
| CVE-2026-16982 |
|
Out-of-Bounds Write in dos (CVE-2026-16982)
out-of-bounds write in dos (CVE-2026-16982). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16975 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-16967 |
|
Vulnerability in ibm (CVE-2026-16967)
vulnerability in ibm (CVE-2026-16967). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16961 |
|
SQL Injection in sqli (CVE-2026-16961)
SQL injection in sqli (CVE-2026-16961). Confidential information can be exposed externally.
|
| CVE-2026-16908 |
|
Path Traversal in path-traversal (CVE-2026-16908)
path traversal in path-traversal (CVE-2026-16908). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16898 |
|
Vulnerability in ibm (CVE-2026-16898)
vulnerability in ibm (CVE-2026-16898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16896 |
|
Vulnerability in ibm (CVE-2026-16896)
vulnerability in ibm (CVE-2026-16896). Confidential information can be exposed externally.
|
| CVE-2026-16887 |
|
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
|
| CVE-2026-16868 |
|
Vulnerability in dos (CVE-2026-16868)
vulnerability in dos (CVE-2026-16868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16867 |
|
Authentication Bypass in ibm (CVE-2026-16867)
authentication bypass in ibm (CVE-2026-16867). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16815 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and...
|
| CVE-2026-16722 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized...
|
| CVE-2026-16674 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-14875 |
|
Vulnerability in ibm (CVE-2026-14875)
vulnerability in ibm (CVE-2026-14875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13460 |
|
Vulnerability in ibm (CVE-2026-13460)
vulnerability in ibm (CVE-2026-13460). Confidential information can be exposed externally.
|
| CVE-2026-13365 |
|
Cross-Site Request Forgery (CSRF) in ibm (CVE-2026-13365)
vulnerability in ibm (CVE-2026-13365). Data can be tampered with by attackers.
|
| CVE-2026-73482 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73482)
vulnerability in csrf (CVE-2026-73482). Data can be tampered with by attackers.
|
| CVE-2026-72777 |
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
| CVE-2026-18071 |
|
Privilege Escalation in ibm (CVE-2026-18071)
vulnerability in ibm (CVE-2026-18071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17220 |
|
Vulnerability in dos (CVE-2026-17220)
vulnerability in dos (CVE-2026-17220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17197 |
|
Authentication Bypass in ibm (CVE-2026-17197)
authentication bypass in ibm (CVE-2026-17197). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58374 |
|
SQL Injection in sqli (CVE-2024-58374)
SQL injection in sqli (CVE-2024-58374). Confidential information can be exposed externally.
|
| CVE-2026-59109 |
|
Vulnerability in sqli (CVE-2026-59109)
vulnerability in sqli (CVE-2026-59109). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72741 |
|
Vulnerability in CVE-2026-72741 (CVE-2026-72741)
vulnerability in CVE-2026-72741 (CVE-2026-72741). Confidential information can be exposed externally.
|
| CVE-2019-25765 |
|
SQL Injection in sqli (CVE-2019-25765)
SQL injection in sqli (CVE-2019-25765). Confidential information can be exposed externally.
|
| CVE-2026-73266 |
|
Vulnerability in CVE-2026-73266 (CVE-2026-73266)
vulnerability in CVE-2026-73266 (CVE-2026-73266). Confidential information can be exposed externally.
|
| CVE-2026-13048 |
|
Path Traversal in CVE-2026-13048 (CVE-2026-13048)
path traversal in CVE-2026-13048 (CVE-2026-13048). Data can be tampered with by attackers.
|
| CVE-2026-73566 |
|
Vulnerability in tar (CVE-2026-73566)
vulnerability in tar (CVE-2026-73566). Risk of unauthorized operations or information disclosure. Exploitable via ``tar``. Mitigation: upgrade to `7.5.21` or later.
|
| CVE-2026-18428 |
|
Vulnerability in Amazon aws (CVE-2026-18428)
vulnerability in Amazon aws (CVE-2026-18428). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7639 |
|
Unsafe Deserialization in cisa (CVE-2025-7639)
vulnerability in cisa (CVE-2025-7639). Data can be tampered with by attackers.
|