Common Vulnerabilities and Exposures (CVE)

CVE-2026-17110

Aug 15, 2026 03:55:36 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.

CVE-2026-14525

Aug 15, 2026 03:55:35 UTC

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.

CVE-2026-16722

Aug 15, 2026 03:55:34 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

CVE-2026-16867

Aug 15, 2026 03:55:33 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.

CVE-2026-73327

Aug 15, 2026 03:55:31 UTC

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filename...

CVE-2020-0618

Aug 15, 2026 03:55:30 UTC

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

CVE-2026-16907

Aug 15, 2026 03:55:30 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

CVE-2021-4034

Aug 15, 2026 03:55:29 UTC

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current ver...

CVE-2026-16856

Aug 15, 2026 03:55:29 UTC

IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

CVE-2022-21882

Aug 15, 2026 03:55:27 UTC

Win32k Elevation of Privilege Vulnerability

CVE-2025-60710

Aug 15, 2026 03:55:27 UTC

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2019-5591

Aug 15, 2026 03:55:26 UTC

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

CVE-2020-29574

Aug 15, 2026 03:55:26 UTC

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

CVE-2026-16145

Aug 15, 2026 03:25:59 UTC

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitiz...

CVE-2026-13360

Aug 15, 2026 03:25:59 UTC

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and...