Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-73739 | MEDIUM | Patched | 4.4 | 2026-09-01 | A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a cleartex… |
| CVE-2026-73740 | MEDIUM | Patched | 4.4 | 2026-09-01 | A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privi… |
| CVE-2026-73741 | MEDIUM | Patched | 4.3 | 2026-09-01 | A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation cou… |
| CVE-2026-73742 | MEDIUM | Patched | 4.3 | 2026-09-01 | A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to thei… |
| CVE-2026-73743 | LOW | Patched | 3.7 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handle… |
| CVE-2026-73744 | LOW | Patched | 3.5 | 2026-09-01 | A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator us… |
| CVE-2026-73745 | LOW | Patched | 3.1 | 2026-09-01 | A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system… |
| CVE-2026-73746 | LOW | Patched | 3.1 | 2026-09-01 | A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of ser… |
| CVE-2026-73747 | LOW | Patched | 2.5 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato… |
| CVE-2026-73748 | LOW | Patched | 2.2 | 2026-09-01 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext… |
| CVE-2026-76657 | CRITICAL | Patched | 10.0 | 2026-09-01 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing aut… |
| CVE-2026-76658 | CRITICAL | Patched | 10.0 | 2026-09-01 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to… |
| CVE-2026-77221 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77222 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77223 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-78592 | HIGH | Patched | 7.3 | 2026-09-01 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Tra… |
| CVE-2026-78597 | MEDIUM | Patched | 4.3 | 2026-09-01 | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs… |
| CVE-2026-78603 | MEDIUM | Patched | 4.3 | 2026-09-01 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authentica… |
| CVE-2026-78605 | MEDIUM | Patched | 5.9 | 2026-09-01 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33).… |
| CVE-2026-78606 | MEDIUM | Patched | 4.2 | 2026-09-01 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by … |
| CVE-2026-78607 | MEDIUM | Patched | 5.4 | 2026-09-01 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only infere… |
| CVE-2026-78608 | MEDIUM | Patched | 6.5 | 2026-09-01 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana… |
| CVE-2026-84307 | LOW | Patched | 3.7 | 2026-09-01 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents … |
| CVE-2026-84308 | MEDIUM | Patched | 6.3 | 2026-09-01 | phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-de… |
| CVE-2026-84309 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py T… |