Export limit exceeded: 403622 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403622 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76742 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.8 Critical |
| Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system. | ||||
| CVE-2026-76743 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.8 Critical |
| A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system. | ||||
| CVE-2026-76744 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.8 Critical |
| Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code. | ||||
| CVE-2026-76745 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.6 Critical |
| Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code. | ||||
| CVE-2026-78017 | 2026-10-09 | 3.8 Low | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass. | ||||
| CVE-2026-76746 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.3 Critical |
| An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device. | ||||
| CVE-2026-76747 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.1 Critical |
| Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device. | ||||
| CVE-2026-76748 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 8.8 High |
| A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system. | ||||
| CVE-2026-76749 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 6.5 Medium |
| A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information. | ||||
| CVE-2026-76061 | 2 Cri-o, Redhat | 3 Cri-o, Openshift, Openshift Container Platform | 2026-10-09 | 5.5 Medium |
| A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system. | ||||
| CVE-2026-102413 | 1 Elastic | 2 Elastic Agent, Elastic Defend | 2026-10-09 | 6.2 Medium |
| Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists. | ||||
| CVE-2026-104047 | 2 Redhat, Sssd | 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more | 2026-10-09 | 5.3 Medium |
| A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory. | ||||
| CVE-2026-106063 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-10-09 | 6.3 Medium |
| A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer, after integer overflow in the allocation size | ||||
| CVE-2026-101153 | 1 Arista | 2 Cloudvision Portal, Cloudvision Sensor | 2026-10-09 | 8 High |
| On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. | ||||
| CVE-2026-102155 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 8.5 High |
| An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service. | ||||
| CVE-2026-102157 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 5.9 Medium |
| An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data. | ||||
| CVE-2026-102158 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 6.5 Medium |
| Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability. | ||||
| CVE-2026-102159 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 9.8 Critical |
| An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services. | ||||
| CVE-2026-102160 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 7.2 High |
| An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service. | ||||
| CVE-2026-102161 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 8.8 High |
| An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend. | ||||