Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73707 | HIGH | 8.5 | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing … | Sep 01, 2026 |
| CVE-2026-73706 | HIGH | 8.6 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the … | Sep 01, 2026 |
| CVE-2026-73705 | HIGH | 8.8 | An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful … | Sep 01, 2026 |
| CVE-2026-73704 | HIGH | 8.8 | A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate … | Sep 01, 2026 |
| CVE-2026-73703 | HIGH | 8.8 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) … | Sep 01, 2026 |
| CVE-2026-73702 | HIGH | 8.8 | A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate … | Sep 01, 2026 |
| CVE-2026-73701 | CRITICAL | 9.0 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside … | Sep 01, 2026 |
| CVE-2026-73700 | CRITICAL | 9.0 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site … | Sep 01, 2026 |
| CVE-2026-72682 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding … | Sep 01, 2026 |
| CVE-2026-72654 | MEDIUM | 6.5 | Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users … | Sep 01, 2026 |
| CVE-2026-72652 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can … | Sep 01, 2026 |
| CVE-2026-72649 | HIGH | 8.8 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained … | Sep 01, 2026 |
| CVE-2026-72644 | MEDIUM | 6.5 | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature … | Sep 01, 2026 |
| CVE-2026-72641 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding … | Sep 01, 2026 |
| CVE-2026-72633 | MEDIUM | 4.3 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An … | Sep 01, 2026 |
| CVE-2026-72628 | MEDIUM | 6.5 | Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams … | Sep 01, 2026 |
| CVE-2026-63138 | MEDIUM | 6.5 | Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with … | Sep 01, 2026 |
| CVE-2026-63137 | HIGH | 8.3 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions … | Sep 01, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated … | Sep 01, 2026 |
| CVE-2026-45221 | HIGH | 7.8 | Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files … | Sep 01, 2026 |
| CVE-2026-33465 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with … | Sep 01, 2026 |
| CVE-2026-19766 | CRITICAL | 9.6 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute … | Sep 01, 2026 |
| CVE-2026-8712 | HIGH | 8.3 | Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying … | Sep 01, 2026 |
| CVE-2026-84306 | MEDIUM | 6.5 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key … | Sep 01, 2026 |
| CVE-2026-84305 | UNKNOWN | — | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in … | Sep 01, 2026 |