Export limit exceeded: 403672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403672 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-76746 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.3 Critical
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
CVE-2026-76747 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.1 Critical
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.
CVE-2026-76748 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 8.8 High
A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system.
CVE-2026-76749 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 6.5 Medium
A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information.
CVE-2026-76061 2 Cri-o, Redhat 3 Cri-o, Openshift, Openshift Container Platform 2026-10-09 5.5 Medium
A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.
CVE-2026-102413 1 Elastic 2 Elastic Agent, Elastic Defend 2026-10-09 6.2 Medium
Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists.
CVE-2026-106063 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 6.3 Medium
A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer, after integer overflow in the allocation size
CVE-2026-101153 1 Arista 2 Cloudvision Portal, Cloudvision Sensor 2026-10-09 8 High
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
CVE-2026-102155 1 Arista 1 Cloudvision Cue 2026-10-09 8.5 High
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.
CVE-2026-102157 1 Arista 1 Cloudvision Cue 2026-10-09 5.9 Medium
An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data.
CVE-2026-102158 1 Arista 1 Cloudvision Cue 2026-10-09 6.5 Medium
Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.
CVE-2026-102159 1 Arista 1 Cloudvision Cue 2026-10-09 9.8 Critical
An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.
CVE-2026-102160 1 Arista 1 Cloudvision Cue 2026-10-09 7.2 High
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
CVE-2026-102161 1 Arista 1 Cloudvision Cue 2026-10-09 8.8 High
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
CVE-2026-102156 1 Arista 1 Cloudvision Cue 2026-10-09 6.8 Medium
Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service.
CVE-2026-101156 1 Arista 1 Cloudvision Cue 2026-10-09 8.4 High
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services.
CVE-2026-101157 1 Arista 1 Cloudvision Cue 2026-10-09 8.7 High
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
CVE-2026-102162 1 Arista 1 Wi-fi Access Points 2026-10-09 8.8 High
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.
CVE-2026-102168 1 Arista 1 Wi-fi Access Points 2026-10-09 6.5 Medium
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.
CVE-2026-102169 1 Arista 1 Wi-fi Access Points 2026-10-09 6.5 Medium
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.