Export limit exceeded: 403644 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403644 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 16908 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403644 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403644 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102158 1 Arista 1 Cloudvision Cue 2026-10-09 6.5 Medium
Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.
CVE-2026-102159 1 Arista 1 Cloudvision Cue 2026-10-09 9.8 Critical
An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.
CVE-2026-102160 1 Arista 1 Cloudvision Cue 2026-10-09 7.2 High
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
CVE-2026-102161 1 Arista 1 Cloudvision Cue 2026-10-09 8.8 High
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
CVE-2026-102156 1 Arista 1 Cloudvision Cue 2026-10-09 6.8 Medium
Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service.
CVE-2026-101156 1 Arista 1 Cloudvision Cue 2026-10-09 8.4 High
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services.
CVE-2026-101157 1 Arista 1 Cloudvision Cue 2026-10-09 8.7 High
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
CVE-2026-102162 1 Arista 1 Wi-fi Access Points 2026-10-09 8.8 High
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.
CVE-2026-102168 1 Arista 1 Wi-fi Access Points 2026-10-09 6.5 Medium
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.
CVE-2026-102169 1 Arista 1 Wi-fi Access Points 2026-10-09 6.5 Medium
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.
CVE-2026-102163 1 Arista 1 Wi-fi Access Points 2026-10-09 8.8 High
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.
CVE-2026-102164 1 Arista 1 Wi-fi Access Points 2026-10-09 3.1 Low
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.
CVE-2026-102167 1 Arista 1 Wi-fi Access Points 2026-10-09 7.5 High
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.
CVE-2026-102165 1 Arista 1 Wi-fi Access Points 2026-10-09 7.5 High
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.
CVE-2026-106447 1 Stablelib 1 Stablelib 2026-10-09 N/A
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
CVE-2026-105111 1 Apache 1 Apache Commons Bcel 2026-10-09 4.7 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports). This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
CVE-2026-106448 1 Stablelib 1 Stablelib 2026-10-09 N/A
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. Downstream code that trusts normal property lookup or merges the decoded object can therefore make security-sensitive decisions using inherited attacker data. This issue is fixed in version 2.0.4.
CVE-2026-105244 1 Apache 1 Log4net 2026-10-09 5.3 Medium
Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
CVE-2026-101258 2 Ghostscript, Redhat 2 Ghostscript, Enterprise Linux 2026-10-09 7.8 High
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript.
CVE-2026-106062 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 7.8 High
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL, following integer overflow in size calculations. This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process.