U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-16687 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the F... read CVE-2026-16687
    Published: August 19, 2026; 3:17:10 PM -0400

  • CVE-2026-16922 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
    Published: August 20, 2026; 11:17:28 AM -0400

  • CVE-2026-16923 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
    Published: August 20, 2026; 11:17:28 AM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-16924 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
    Published: August 20, 2026; 11:17:28 AM -0400

  • CVE-2026-16925 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization.
    Published: August 20, 2026; 11:17:28 AM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-16927 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
    Published: August 20, 2026; 11:17:29 AM -0400

    V3.1: 7.0 HIGH

  • CVE-2026-16928 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
    Published: August 20, 2026; 11:17:29 AM -0400

  • CVE-2026-16932 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable.
    Published: August 20, 2026; 11:17:29 AM -0400

  • CVE-2026-16930 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/... read CVE-2026-16930
    Published: August 19, 2026; 3:17:10 PM -0400

  • CVE-2026-16989 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.
    Published: August 20, 2026; 6:17:10 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-21962 - Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that ar... read CVE-2026-21962
    Published: January 20, 2026; 5:15:59 PM -0500

  • CVE-2026-16991 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
    Published: August 20, 2026; 6:17:10 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-17015 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
    Published: August 19, 2026; 5:16:54 PM -0400

    V3.1: 8.1 HIGH

  • CVE-2026-18102 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.
    Published: August 19, 2026; 5:16:54 PM -0400

    V3.1: 4.3 MEDIUM

  • CVE-2025-36254 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cau... read CVE-2025-36254
    Published: August 19, 2026; 6:16:36 PM -0400

  • CVE-2025-36398 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
    Published: August 19, 2026; 6:16:36 PM -0400

  • CVE-2026-76398 - In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerabilit... read CVE-2026-76398
    Published: August 19, 2026; 6:17:26 PM -0400

  • CVE-2026-76399 - In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access ... read CVE-2026-76399
    Published: August 19, 2026; 6:17:26 PM -0400

    V3.1: 8.1 HIGH

  • CVE-2025-36255 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.
    Published: August 19, 2026; 6:16:36 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-76400 - In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splu... read CVE-2026-76400
    Published: August 19, 2026; 6:17:26 PM -0400