The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-16879 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
Published: August 14, 2026; 4:16:49 PM -0400 -
CVE-2026-16905 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
Published: August 14, 2026; 4:16:49 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-16915 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
Published: August 14, 2026; 4:16:49 PM -0400 -
CVE-2026-17079 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
Published: August 14, 2026; 4:16:50 PM -0400V3.1: 4.3 MEDIUM
-
CVE-2026-17081 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
Published: August 14, 2026; 4:16:50 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-17173 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
Published: August 14, 2026; 4:16:50 PM -0400 -
CVE-2026-17175 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Published: August 14, 2026; 4:16:50 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17177 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
Published: August 14, 2026; 4:16:50 PM -0400 -
CVE-2026-17179 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
Published: August 14, 2026; 4:16:50 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17181 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
Published: August 14, 2026; 4:16:50 PM -0400V3.1: 8.6 HIGH
-
CVE-2026-17182 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
Published: August 14, 2026; 4:16:50 PM -0400 -
CVE-2026-74936 - Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: August 18, 2026; 9:17:29 AM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-74940 - Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: August 18, 2026; 9:17:30 AM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-74943 - Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: August 18, 2026; 9:17:30 AM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-74944 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: August 18, 2026; 9:17:30 AM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-74961 - Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: August 18, 2026; 9:17:33 AM -0400 -
CVE-2026-74968 - Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: August 18, 2026; 9:17:34 AM -0400 -
CVE-2026-74245 - A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email o... read CVE-2026-74245
Published: August 14, 2026; 7:16:34 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-74244 - A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Sign... read CVE-2026-74244
Published: August 14, 2026; 7:16:34 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-74247 - A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing t... read CVE-2026-74247
Published: August 14, 2026; 7:16:34 PM -0400V3.1: 7.1 HIGH