Total
398551 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-18077 | 1 Ibm | 1 I | 2026-08-19 | N/A | 7.5 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. | |||||
| CVE-2026-18068 | 1 Ibm | 1 I | 2026-08-19 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion. | |||||
| CVE-2026-18020 | 1 Ibm | 1 I | 2026-08-19 | N/A | 5.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking. | |||||
| CVE-2026-17502 | 1 Ibm | 1 I | 2026-08-19 | N/A | 8.6 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | |||||
| CVE-2026-17649 | 1 Ibm | 1 I | 2026-08-19 | N/A | 5.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. | |||||
| CVE-2026-17076 | 1 Ibm | 1 I | 2026-08-19 | N/A | 5.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests. | |||||
| CVE-2026-17074 | 1 Ibm | 1 I | 2026-08-19 | N/A | 3.1 LOW |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management. | |||||
| CVE-2026-17071 | 1 Ibm | 1 I | 2026-08-19 | N/A | 2.7 LOW |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal. | |||||
| CVE-2026-19228 | 1 Gitlab | 1 Gitlab | 2026-08-19 | N/A | 8.5 HIGH |
| GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests. | |||||
| CVE-2026-18433 | 1 Gitlab | 1 Gitlab | 2026-08-19 | N/A | 4.3 MEDIUM |
| GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query. | |||||
| CVE-2026-16494 | 1 Gitlab | 1 Gitlab | 2026-08-19 | N/A | 7.1 HIGH |
| GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint. | |||||
| CVE-2026-21077 | 1 Samsung | 1 Health | 2026-08-19 | N/A | 5.5 MEDIUM |
| Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |||||
| CVE-2025-9486 | 1 Gitlab | 1 Gitlab | 2026-08-19 | N/A | 3.3 LOW |
| GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state. | |||||
| CVE-2026-18197 | 1 Ylefebvre | 1 Link Library | 2026-08-19 | N/A | 6.1 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4. | |||||
| CVE-2026-21078 | 1 Samsung | 1 Smart Switch | 2026-08-19 | N/A | 6.5 MEDIUM |
| Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. | |||||
| CVE-2026-13463 | 1 Ibm | 2 Aix, Cloud Pak System | 2026-08-19 | N/A | 7.5 HIGH |
| IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. | |||||
| CVE-2026-21080 | 1 Samsung | 1 Smart Switch | 2026-08-19 | N/A | 6.5 MEDIUM |
| Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | |||||
| CVE-2026-21082 | 1 Samsung | 1 Health | 2026-08-19 | N/A | 5.5 MEDIUM |
| Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |||||
| CVE-2026-63102 | 1 Rconfig | 1 Rconfig | 2026-08-19 | N/A | 5.4 MEDIUM |
| rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected. | |||||
| CVE-2026-21083 | 1 Samsung | 1 Smart Switch | 2026-08-19 | N/A | 6.5 MEDIUM |
| Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | |||||
