CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-73778
8.1 HIGH

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a …

Sep 1, 2026
CVE-2026-73777
8.1 HIGH

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

Sep 1, 2026
CVE-2026-73776
7.9 HIGH

A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to …

Sep 1, 2026
CVE-2026-73775
7.7 HIGH

Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an …

Sep 1, 2026
CVE-2026-73774
7.6 HIGH

A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted …

Sep 1, 2026
CVE-2026-73773
7.5 HIGH

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal …

Sep 1, 2026
CVE-2026-73771
7.5 HIGH

An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability …

Sep 1, 2026
CVE-2026-73770
7.3 HIGH

An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and …

Sep 1, 2026
CVE-2026-73768
7.3 HIGH

A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the …

Sep 1, 2026
CVE-2026-73767
7.2 HIGH

Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands …

Sep 1, 2026
CVE-2026-73766
7.2 HIGH

Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could …

Sep 1, 2026
CVE-2026-73765
7.2 HIGH

Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying …

Sep 1, 2026
CVE-2026-73764
7.1 HIGH

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In …

Sep 1, 2026
CVE-2026-73763
7.1 HIGH

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution …

Sep 1, 2026
CVE-2026-73753
8.8 HIGH

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Sep 1, 2026
CVE-2026-73752
8.8 HIGH

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files …

Sep 1, 2026
CVE-2026-73751
8.8 HIGH

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

Sep 1, 2026
CVE-2026-73750
8.8 HIGH

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially …

Sep 1, 2026
CVE-2026-71981
8.8 HIGH

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object …

Sep 1, 2026
CVE-2026-78592
7.3 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path …

Sep 1, 2026
CVE-2026-73725
7.0 HIGH

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary …

Sep 1, 2026
CVE-2026-73724
7.1 HIGH

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the …

Sep 1, 2026
CVE-2026-73723
7.1 HIGH

A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user …

Sep 1, 2026
CVE-2026-73722
7.2 HIGH

Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the …

Sep 1, 2026
CVE-2026-73721
7.2 HIGH

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric …

Sep 1, 2026
CVE-2026-73720
7.2 HIGH

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could …

Sep 1, 2026
CVE-2026-73719
7.2 HIGH

An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful …

Sep 1, 2026
CVE-2026-73718
7.4 HIGH

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker …

Sep 1, 2026
CVE-2026-73717
7.5 HIGH

A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary …

Sep 1, 2026
CVE-2026-73716
7.5 HIGH

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run …

Sep 1, 2026
CVE-2026-73715
7.5 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Sep 1, 2026
CVE-2026-73714
7.6 HIGH

A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to …

Sep 1, 2026
CVE-2026-73713
7.8 HIGH

Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code …

Sep 1, 2026
CVE-2026-73712
8.1 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if …

Sep 1, 2026
CVE-2026-73711
8.1 HIGH

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative …

Sep 1, 2026
CVE-2026-73710
8.2 HIGH

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Sep 1, 2026
CVE-2026-73709
8.3 HIGH

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying …

Sep 1, 2026
CVE-2026-73708
8.3 HIGH

A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain …

Sep 1, 2026
CVE-2026-73707
8.5 HIGH

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing …

Sep 1, 2026
CVE-2026-73706
8.6 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the …

Sep 1, 2026
CVE-2026-73705
8.8 HIGH

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful …

Sep 1, 2026
CVE-2026-73704
8.8 HIGH

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate …

Sep 1, 2026
CVE-2026-73703
8.8 HIGH

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) …

Sep 1, 2026
CVE-2026-73702
8.8 HIGH

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate …

Sep 1, 2026
CVE-2026-72649
8.8 HIGH

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained …

Sep 1, 2026
CVE-2026-63137
8.3 HIGH

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions …

Sep 1, 2026
CVE-2026-45221
7.8 HIGH

Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files …

Sep 1, 2026
CVE-2026-8712
8.3 HIGH

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying …

Sep 1, 2026
CVE-2026-83551
7.2 HIGH

Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an …

Sep 1, 2026
CVE-2026-52130
7.5 HIGH

llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.