Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84365 | MEDIUM | 6.5 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover … | Sep 01, 2026 |
| CVE-2026-84364 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested … | Sep 01, 2026 |
| CVE-2026-84363 | MEDIUM | 5.9 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a … | Sep 01, 2026 |
| CVE-2026-84361 | UNKNOWN | — | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or … | Sep 01, 2026 |
| CVE-2026-84311 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to … | Sep 01, 2026 |
| CVE-2026-84310 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long … | Sep 01, 2026 |
| CVE-2026-84287 | MEDIUM | 4.3 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session … | Sep 01, 2026 |
| CVE-2026-73783 | MEDIUM | 4.9 | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the … | Sep 01, 2026 |
| CVE-2026-73782 | HIGH | 8.8 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability … | Sep 01, 2026 |
| CVE-2026-73781 | HIGH | 8.4 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an … | Sep 01, 2026 |
| CVE-2026-73780 | HIGH | 8.3 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow … | Sep 01, 2026 |
| CVE-2026-73779 | HIGH | 8.2 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful … | Sep 01, 2026 |
| CVE-2026-73778 | HIGH | 8.1 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a … | Sep 01, 2026 |
| CVE-2026-73777 | HIGH | 8.1 | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. | Sep 01, 2026 |
| CVE-2026-73776 | HIGH | 7.9 | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to … | Sep 01, 2026 |
| CVE-2026-73775 | HIGH | 7.7 | Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an … | Sep 01, 2026 |
| CVE-2026-73774 | HIGH | 7.6 | A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted … | Sep 01, 2026 |
| CVE-2026-73773 | HIGH | 7.5 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal … | Sep 01, 2026 |
| CVE-2026-73772 | MEDIUM | 6.5 | Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the … | Sep 01, 2026 |
| CVE-2026-73771 | HIGH | 7.5 | An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability … | Sep 01, 2026 |
| CVE-2026-73770 | HIGH | 7.3 | An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and … | Sep 01, 2026 |
| CVE-2026-73768 | HIGH | 7.3 | A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the … | Sep 01, 2026 |
| CVE-2026-73767 | HIGH | 7.2 | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands … | Sep 01, 2026 |
| CVE-2026-73766 | HIGH | 7.2 | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could … | Sep 01, 2026 |
| CVE-2026-73765 | HIGH | 7.2 | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying … | Sep 01, 2026 |