Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73764 | HIGH | 7.1 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In … | Sep 01, 2026 |
| CVE-2026-73763 | HIGH | 7.1 | A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution … | Sep 01, 2026 |
| CVE-2026-73762 | MEDIUM | 6.6 | A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases … | Sep 01, 2026 |
| CVE-2026-73761 | MEDIUM | 6.5 | An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. … | Sep 01, 2026 |
| CVE-2026-73760 | MEDIUM | 6.5 | An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface … | Sep 01, 2026 |
| CVE-2026-73759 | MEDIUM | 6.5 | Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities … | Sep 01, 2026 |
| CVE-2026-73758 | MEDIUM | 6.5 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state … | Sep 01, 2026 |
| CVE-2026-73757 | MEDIUM | 6.4 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful … | Sep 01, 2026 |
| CVE-2026-73756 | MEDIUM | 5.9 | A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows … | Sep 01, 2026 |
| CVE-2026-73755 | MEDIUM | 5.7 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, … | Sep 01, 2026 |
| CVE-2026-73754 | MEDIUM | 5.3 | Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable … | Sep 01, 2026 |
| CVE-2026-73753 | HIGH | 8.8 | Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. | Sep 01, 2026 |
| CVE-2026-73752 | HIGH | 8.8 | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files … | Sep 01, 2026 |
| CVE-2026-73751 | HIGH | 8.8 | An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. | Sep 01, 2026 |
| CVE-2026-73750 | HIGH | 8.8 | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially … | Sep 01, 2026 |
| CVE-2026-73749 | CRITICAL | 9.8 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities … | Sep 01, 2026 |
| CVE-2026-73524 | MEDIUM | 6.1 | Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads … | Sep 01, 2026 |
| CVE-2026-71981 | HIGH | 8.8 | Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object … | Sep 01, 2026 |
| CVE-2026-63435 | MEDIUM | 5.3 | Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match … | Sep 01, 2026 |
| CVE-2026-84309 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child … | Sep 01, 2026 |
| CVE-2026-84308 | MEDIUM | 6.3 | phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() … | Sep 01, 2026 |
| CVE-2026-84307 | LOW | 3.7 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating … | Sep 01, 2026 |
| CVE-2026-78608 | MEDIUM | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM … | Sep 01, 2026 |
| CVE-2026-78607 | MEDIUM | 5.4 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges … | Sep 01, 2026 |
| CVE-2026-78606 | MEDIUM | 4.2 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where … | Sep 01, 2026 |