Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 126–150 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73717 | HIGH | 7.5 | 2026-09-01 | A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run … | |
| CVE-2026-73716 | HIGH | 7.5 | 2026-09-01 | A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run… | |
| CVE-2026-73715 | HIGH | 7.5 | 2026-09-01 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation c… | |
| CVE-2026-73714 | HIGH | 7.6 | 2026-09-01 | A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege ope… | |
| CVE-2026-73713 | HIGH | 7.8 | 2026-09-01 | Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local atta… | |
| CVE-2026-73712 | HIGH | 8.1 | 2026-09-01 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain prec… | |
| CVE-2026-73711 | HIGH | 8.1 | 2026-09-01 | A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to… | |
| CVE-2026-73710 | HIGH | 8.2 | 2026-09-01 | Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploi… | |
| CVE-2026-73709 | HIGH | 8.3 | 2026-09-01 | A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the under… | |
| CVE-2026-73708 | HIGH | 8.3 | 2026-09-01 | A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obta… | |
| CVE-2026-73707 | HIGH | 8.5 | 2026-09-01 | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to… | |
| CVE-2026-73706 | HIGH | 8.6 | 2026-09-01 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of … | |
| CVE-2026-73705 | HIGH | 8.8 | 2026-09-01 | An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successf… | |
| CVE-2026-73704 | HIGH | 8.8 | 2026-09-01 | A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escal… | |
| CVE-2026-73703 | HIGH | 8.8 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scri… | |
| CVE-2026-73702 | HIGH | 8.8 | 2026-09-01 | A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user t… | |
| CVE-2026-73701 | CRITICAL | 9.0 | 2026-09-01 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond… | |
| CVE-2026-73700 | CRITICAL | 9.0 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s… | |
| CVE-2026-72682 | MEDIUM | 6.5 | 2026-09-01 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding… | |
| CVE-2026-72654 | MEDIUM | 6.5 | 2026-09-01 | Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation avai… | |
| CVE-2026-72652 | MEDIUM | 6.5 | 2026-09-01 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can sub… | |
| CVE-2026-72649 | HIGH | 8.8 | 2026-09-01 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially … | |
| CVE-2026-72644 | MEDIUM | 6.5 | 2026-09-01 | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged featur… | |
| CVE-2026-72641 | MEDIUM | 5.4 | 2026-09-01 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authent… | |
| CVE-2026-72633 | MEDIUM | 4.3 | 2026-09-01 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1… |