Total
398567 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-16722 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management. | |||||
| CVE-2019-25758 | 1 Wdmtech | 1 Vbizz | 2026-08-17 | N/A | 8.8 HIGH |
| Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution. | |||||
| CVE-2019-25759 | 1 Wdmtech | 1 Vbizz | 2026-08-17 | N/A | 7.1 HIGH |
| Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names. | |||||
| CVE-2026-62881 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-08-17 | N/A | 6.7 MEDIUM |
| Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62883 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-08-17 | N/A | 6.7 MEDIUM |
| Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-17485 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.2 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. | |||||
| CVE-2026-16908 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.5 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability. | |||||
| CVE-2026-16871 | 1 Ibm | 1 I | 2026-08-17 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow. | |||||
| CVE-2026-16961 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.6 HIGH |
| IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |||||
| CVE-2026-59092 | 1 Juicedata | 1 Juicefs | 2026-08-17 | N/A | 7.7 HIGH |
| JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline endpoint to obtain the process command line containing metadata engine connection strings with database credentials, granting full read/write access to filesystem metadata, while other pprof handlers leak internal state and profiling handlers enable denial of service. | |||||
| CVE-2026-17029 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. | |||||
| CVE-2026-17043 | 1 Ibm | 1 I | 2026-08-17 | N/A | 3.8 LOW |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. | |||||
| CVE-2026-58231 | 2026-08-17 | N/A | 10.0 CRITICAL | ||
| SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. | |||||
| CVE-2026-17069 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens. | |||||
| CVE-2026-9646 | 1 Scadabr | 1 Scadabr | 2026-08-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting issue exists in URL handling. | |||||
| CVE-2026-9645 | 1 Scadabr | 1 Scadabr | 2026-08-17 | N/A | 9.9 CRITICAL |
| Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root. | |||||
| CVE-2026-17199 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.5 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation. | |||||
| CVE-2026-17206 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | |||||
| CVE-2026-17223 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. | |||||
| CVE-2026-17229 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.5 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop. | |||||
