NVD Dashboard
CVEs Received and Processed
NVD Contains
| CVE Vulnerabilities | 376868 |
| Checklists | 913 |
| US-CERT Alerts | 249 |
| US-CERT Vuln Notes | 4486 |
| OVAL Queries | 0 |
| CPE Names | 1800697 |
CVSS V3 Score Distribution
| Severity | Number of Vulns |
|---|
CVSS V2 Score Distribution
| Severity | Number of Vulns |
|---|
For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
-
CVE-2026-17110 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
Published: August 12, 2026; 2:17:25 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-17218 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Published: August 12, 2026; 2:17:25 PM -0400 -
CVE-2026-17222 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command.
Published: August 12, 2026; 2:17:26 PM -0400 -
CVE-2026-17248 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17266 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17268 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session token.
Published: August 12, 2026; 2:17:26 PM -0400 -
CVE-2026-17271 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-17276 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 9.9 CRITICAL
-
CVE-2026-18713 - IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
Published: August 12, 2026; 2:17:28 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-18669 - IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
Published: August 12, 2026; 2:17:28 PM -0400 -
CVE-2026-18250 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition.
Published: August 12, 2026; 2:17:28 PM -0400V3.1: 5.0 MEDIUM
-
CVE-2026-18235 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
Published: August 12, 2026; 2:17:28 PM -0400 -
CVE-2026-17420 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.
Published: August 12, 2026; 2:17:27 PM -0400 -
CVE-2026-17419 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17418 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-58484 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes ... read CVE-2026-58484
Published: July 20, 2026; 1:18:16 PM -0400 -
CVE-2026-58482 - Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate` uses to... read CVE-2026-58482
Published: July 20, 2026; 1:18:15 PM -0400 -
CVE-2026-58481 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox base suc... read CVE-2026-58481
Published: July 20, 2026; 1:18:15 PM -0400 -
CVE-2026-58414 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If... read CVE-2026-58414
Published: July 20, 2026; 1:18:15 PM -0400 -
CVE-2026-18477 - A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the sys... read CVE-2026-18477
Published: August 03, 2026; 1:16:33 PM -0400