Export limit exceeded: 400982 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400982 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-76724 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 9.6 Critical
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76725 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 9.6 Critical
A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.
CVE-2026-47498 1 Nvidia 1 Virtual Gpu Manager 2026-10-01 7.8 High
NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVE-2026-100822 1 Mozilla 1 Firefox 2026-10-01 5.4 Medium
Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-102728 1 Eclipse 1 Netx Duo 2026-10-01 7.5 High
Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.
CVE-2026-103270 1 Modeltc 1 Lightllm 2026-10-01 7.5 High
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
CVE-2026-76727 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 7.2 High
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76732 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 6.4 Medium
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
CVE-2026-76736 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 3.3 Low
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
CVE-2026-76737 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 3 Low
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
CVE-2026-51852 2026-10-01 N/A
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
CVE-2026-100257 1 Jetbrains 1 Youtrack 2026-10-01 4.3 Medium
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-47548 1 Nvidia 6 Geforce, Nvs, Quadro and 3 more 2026-10-01 7.8 High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-47571 1 Nvidia 8 Geforce, Guest Driver, Nvs and 5 more 2026-10-01 7.8 High
NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypass an authorization check that is intended to restrict certain operations based on client execution context. A successful exploit of this vulnerability might lead to escalation of privilege, information disclosure, data tampering, denial of service, or code execution.
CVE-2026-47572 1 Nvidia 5 Geforce, Nvs, Quadro and 2 more 2026-10-01 7.8 High
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-100288 1 Devolutions 1 Server 2026-09-30 7.2 High
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
CVE-2026-95287 1 Google 1 Chrome 2026-09-30 5.4 Medium
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95292 1 Google 1 Chrome 2026-09-30 4.8 Medium
Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
CVE-2026-47575 1 Nvidia 5 Geforce, Nvs, Quadro and 2 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attacker may cause an integer overflow and out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, and code execution.
CVE-2026-47579 1 Nvidia 7 Geforce, Guest Driver, Nvs and 4 more 2026-09-30 7.8 High
The NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-free condition. Successful exploitation of this issue could lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.