Export limit exceeded: 400982 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400982 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76724 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 9.6 Critical |
| A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||||
| CVE-2026-76725 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 9.6 Critical |
| A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges. | ||||
| CVE-2026-47498 | 1 Nvidia | 1 Virtual Gpu Manager | 2026-10-01 | 7.8 High |
| NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-100822 | 1 Mozilla | 1 Firefox | 2026-10-01 | 5.4 Medium |
| Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-102728 | 1 Eclipse | 1 Netx Duo | 2026-10-01 | 7.5 High |
| Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard. | ||||
| CVE-2026-103270 | 1 Modeltc | 1 Lightllm | 2026-10-01 | 7.5 High |
| LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl. | ||||
| CVE-2026-76727 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 7.2 High |
| Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||||
| CVE-2026-76732 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 6.4 Medium |
| A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control. | ||||
| CVE-2026-76736 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 3.3 Low |
| A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service. | ||||
| CVE-2026-76737 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 3 Low |
| An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service. | ||||
| CVE-2026-51852 | 2026-10-01 | N/A | ||
| agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. | ||||
| CVE-2026-100257 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||
| CVE-2026-47548 | 1 Nvidia | 6 Geforce, Nvs, Quadro and 3 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47571 | 1 Nvidia | 8 Geforce, Guest Driver, Nvs and 5 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypass an authorization check that is intended to restrict certain operations based on client execution context. A successful exploit of this vulnerability might lead to escalation of privilege, information disclosure, data tampering, denial of service, or code execution. | ||||
| CVE-2026-47572 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-100288 | 1 Devolutions | 1 Server | 2026-09-30 | 7.2 High |
| Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records. | ||||
| CVE-2026-95287 | 1 Google | 1 Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95292 | 1 Google | 1 Chrome | 2026-09-30 | 4.8 Medium |
| Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low) | ||||
| CVE-2026-47575 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attacker may cause an integer overflow and out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, and code execution. | ||||
| CVE-2026-47579 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 7.8 High |
| The NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-free condition. Successful exploitation of this issue could lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | ||||