2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-55089 — Etherpad: A non-admin user with a valid signed token can therefore invoke administrative functions including

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55089

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/OAuth2Provider.ts issues admin: false for configured non-admin users. A non-admin user with a valid signed token can therefore invoke administrative functions including setHTML, set CVSSv3.1 9.9 (CRITICAL)

CWECWE 863VNDEtherpadTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-55085 — Etherpad: Any user with write access to a pad can store markup that executes as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55085

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, including list:number1 and a malicious start value. Any user with write ac CVSSv3.1 9.6 (CRITICAL)

CWECWE 79VNDEtherpadTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-22306 — Download: of code without integrity check, inclusion of functionality from untrusted control sphere, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233. CVSSv3.1 10.0 (CRITICAL)

CWECWE 319CWECWE 829CWECWE 494VNDDownloadTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-19508 — Heap: Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19508

Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request. CVSSv3.1 9.8 (CRITICAL) · EPSS 21th percentile

CWECWE 119VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-19506 — Race: condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19506

Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state. CVSSv3.1 8.1 (HIGH) · EPSS 12th percentile

CWECWE 362VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-19505 — Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19505

Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature. CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-17414 — IBM: PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17414

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacke CVSSv3.1 8.1 (HIGH)

CWECWE 20VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-17091 — IBM: The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17091

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of CVSSv3.1 8.4 (HIGH)

CWECWE 190VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16933 — IBM: Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16933

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, CVSSv3.1 8.2 (HIGH)

CWECWE 190VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16919 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16919

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers. CVSSv3.1 9.8 (CRITICAL)

CWECWE 843VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16917 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16917

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16913 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16913

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16911 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16911

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16909 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16909

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking. CVSSv3.1 8.8 (HIGH)

CWECWE 128VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16903 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16903

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write. CVSSv3.1 9.6 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16901 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16901

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16894 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16894

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16885 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16885

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16882 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16882

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16877 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16877

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16872 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16872

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16865 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16865

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16864 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16864

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16862 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16862

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16857 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16857

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication. CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score