Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-78605 MEDIUM 5.9 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment … Sep 01, 2026
CVE-2026-78603 MEDIUM 4.3 Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch … Sep 01, 2026
CVE-2026-78597 MEDIUM 4.3 Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An … Sep 01, 2026
CVE-2026-78592 HIGH 7.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path … Sep 01, 2026
CVE-2026-77223 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 01, 2026
CVE-2026-77222 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 01, 2026
CVE-2026-77221 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 01, 2026
CVE-2026-76658 CRITICAL 10.0 A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access … Sep 01, 2026
CVE-2026-76657 CRITICAL 10.0 Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. … Sep 01, 2026
CVE-2026-73748 LOW 2.2 A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. … Sep 01, 2026
CVE-2026-73747 LOW 2.5 A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access … Sep 01, 2026
CVE-2026-73746 LOW 3.1 A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial … Sep 01, 2026
CVE-2026-73745 LOW 3.1 A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected … Sep 01, 2026
CVE-2026-73744 LOW 3.5 A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause … Sep 01, 2026
CVE-2026-73743 LOW 3.7 A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled … Sep 01, 2026
CVE-2026-73742 MEDIUM 4.3 A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed … Sep 01, 2026
CVE-2026-73741 MEDIUM 4.3 A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation … Sep 01, 2026
CVE-2026-73740 MEDIUM 4.4 A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges … Sep 01, 2026
CVE-2026-73739 MEDIUM 4.4 A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a … Sep 01, 2026
CVE-2026-73738 MEDIUM 4.7 A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view … Sep 01, 2026
CVE-2026-73737 MEDIUM 4.8 An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate … Sep 01, 2026
CVE-2026-73736 MEDIUM 5.3 A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation … Sep 01, 2026
CVE-2026-73735 MEDIUM 5.4 Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. … Sep 01, 2026
CVE-2026-73734 MEDIUM 5.4 A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to redirect users to an arbitrary URL. Sep 01, 2026
CVE-2026-73733 MEDIUM 5.4 Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation … Sep 01, 2026