Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 76–100 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-73749 CRITICAL 9.8 2026-09-01 Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulne…
CVE-2026-73524 MEDIUM Patched 6.1 2026-09-01 Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malic…
CVE-2026-71981 HIGH Patched 8.8 2026-09-01 Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted …
CVE-2026-63435 MEDIUM Patched 5.3 2026-09-01 Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_d…
CVE-2026-84309 NONE Patched — 2026-09-01 pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py T…
CVE-2026-84308 MEDIUM Patched 6.3 2026-09-01 phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-de…
CVE-2026-84307 LOW Patched 3.7 2026-09-01 Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents …
CVE-2026-78608 MEDIUM 6.5 2026-09-01 Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana…
CVE-2026-78607 MEDIUM 5.4 2026-09-01 Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only infere…
CVE-2026-78606 MEDIUM 4.2 2026-09-01 Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by …
CVE-2026-78605 MEDIUM 5.9 2026-09-01 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33).…
CVE-2026-78603 MEDIUM 4.3 2026-09-01 Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authentica…
CVE-2026-78597 MEDIUM 4.3 2026-09-01 Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs…
CVE-2026-78592 HIGH 7.3 2026-09-01 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Tra…
CVE-2026-77223 NONE — 2026-09-01 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77222 NONE — 2026-09-01 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77221 NONE — 2026-09-01 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76658 CRITICAL 10.0 2026-09-01 A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to…
CVE-2026-76657 CRITICAL 10.0 2026-09-01 Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing aut…
CVE-2026-73748 LOW 2.2 2026-09-01 A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext…
CVE-2026-73747 LOW 2.5 2026-09-01 A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato…
CVE-2026-73746 LOW 3.1 2026-09-01 A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of ser…
CVE-2026-73745 LOW 3.1 2026-09-01 A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system…
CVE-2026-73744 LOW 3.5 2026-09-01 A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator us…
CVE-2026-73743 LOW 3.7 2026-09-01 A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handle…