IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 190VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17157 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17152 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17145 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 269VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17142 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 287VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17141 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH
CVE-2026-17138 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CVSSv3.1 8.1 (HIGH)
CWECWE 121VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17136 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 134VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17122 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17118 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 416VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH
CVE-2026-17060 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.
CVSSv3.1 8.1 (HIGH)
CWECWE 200VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT
CVE-2026-17040 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 120VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH
CVE-2026-17006 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CVSSv3.1 8.3 (HIGH)
CWECWE 787VNDIbmTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH
CVE-2026-17000 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.
CVSSv3.1 8.1 (HIGH)
CWECWE 287VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH
CVE-2026-16996 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow.
CVSSv3.1 8.2 (HIGH)
CWECWE 787VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH
CVE-2026-16936 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow.
CVSSv3.1 8.8 (HIGH)
CVE-2026-19478 is a critical unauthenticated code injection vulnerability in GitLab CE/EE affecting versions 18.2–19.2 via a GraphQL directive flaw (CVSS 9.4). The vulnerability allows remote attackers to modify or delete public projects and user data without authentication; active in-the-wild exploitation was observed within 3 days of disclosure. GitLab released patches on August 17, 2026 (versions 18.11.11, 19.0.8, 19.1.6, 19.2.4); GitLab.com and Dedicated are already patched.
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
CVSSv3.1 8.9 (HIGH)
CWECWE 362VNDTorTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH
CVE-2026-76023 — Linux: Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 913TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH
CVE-2026-76022 — Buffer: overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker
Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH
CVE-2026-76021 — Use: after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote
Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH
CVE-2026-76019 — Incorrect: authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.1 (HIGH)
CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH
CVE-2026-76018 — Privilege: elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)