U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-17110 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
    Published: August 12, 2026; 2:17:25 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-17218 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
    Published: August 12, 2026; 2:17:25 PM -0400

  • CVE-2026-17222 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command.
    Published: August 12, 2026; 2:17:26 PM -0400

  • CVE-2026-17248 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
    Published: August 12, 2026; 2:17:26 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-17266 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
    Published: August 12, 2026; 2:17:26 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-17268 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session token.
    Published: August 12, 2026; 2:17:26 PM -0400

  • CVE-2026-17271 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
    Published: August 12, 2026; 2:17:26 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-17276 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
    Published: August 12, 2026; 2:17:26 PM -0400

    V3.1: 9.9 CRITICAL

  • CVE-2026-18713 - IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
    Published: August 12, 2026; 2:17:28 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-18669 - IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
    Published: August 12, 2026; 2:17:28 PM -0400

  • CVE-2026-18250 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition.
    Published: August 12, 2026; 2:17:28 PM -0400

    V3.1: 5.0 MEDIUM

  • CVE-2026-18235 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
    Published: August 12, 2026; 2:17:28 PM -0400

  • CVE-2026-17420 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.
    Published: August 12, 2026; 2:17:27 PM -0400

  • CVE-2026-17419 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command.
    Published: August 12, 2026; 2:17:26 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-17418 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
    Published: August 12, 2026; 2:17:26 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-58484 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes ... read CVE-2026-58484
    Published: July 20, 2026; 1:18:16 PM -0400

  • CVE-2026-58482 - Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate` uses to... read CVE-2026-58482
    Published: July 20, 2026; 1:18:15 PM -0400

  • CVE-2026-58481 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox base suc... read CVE-2026-58481
    Published: July 20, 2026; 1:18:15 PM -0400

  • CVE-2026-58414 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If... read CVE-2026-58414
    Published: July 20, 2026; 1:18:15 PM -0400

  • CVE-2026-18477 - A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the sys... read CVE-2026-18477
    Published: August 03, 2026; 1:16:33 PM -0400