Total
261 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-16694 | 1 Ibm | 1 I | 2026-08-17 | N/A | 6.4 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2026-17094 | 1 Ibm | 1 I | 2026-08-17 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability. | |||||
| CVE-2026-18098 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw. | |||||
| CVE-2026-18106 | 1 Ibm | 1 I | 2026-08-17 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input. | |||||
| CVE-2026-18847 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i. | |||||
| CVE-2026-18509 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.2 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system. | |||||
| CVE-2026-18511 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.3 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash. | |||||
| CVE-2026-18671 | 1 Ibm | 1 I | 2026-08-17 | N/A | 6.5 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service. | |||||
| CVE-2026-18715 | 1 Ibm | 1 I | 2026-08-17 | N/A | 6.5 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities. | |||||
| CVE-2026-17419 | 1 Ibm | 1 I | 2026-08-17 | N/A | 6.5 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command. | |||||
| CVE-2026-17271 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.5 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. | |||||
| CVE-2026-17266 | 1 Ibm | 1 I | 2026-08-17 | N/A | 6.5 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. | |||||
| CVE-2026-17110 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management. | |||||
| CVE-2026-16907 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.6 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking. | |||||
| CVE-2026-16856 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-16860 | 1 Ibm | 1 I | 2026-08-13 | N/A | 9.9 CRITICAL |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element. | |||||
| CVE-2026-16863 | 1 Ibm | 1 I | 2026-08-13 | N/A | 7.7 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. | |||||
| CVE-2026-16904 | 1 Ibm | 1 I | 2026-08-13 | N/A | 8.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment. | |||||
| CVE-2026-16906 | 1 Ibm | 1 I | 2026-08-13 | N/A | 8.8 HIGH |
| IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-16931 | 1 Ibm | 1 I | 2026-08-13 | N/A | 7.5 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options. | |||||
