| CVE-2026-78603 | MEDIUM | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Config… | 2026-09-01 |
| CVE-2026-78605 | MEDIUM | 5.9 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to… | 2026-09-01 |
| CVE-2026-78606 | MEDIUM | 4.2 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of… | 2026-09-01 |
| CVE-2026-78607 | MEDIUM | 5.4 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosu… | 2026-09-01 |
| CVE-2026-78608 | MEDIUM | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). … | 2026-09-01 |
| CVE-2026-84307 | LOW | 3.7 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5… | 2026-09-01 |
| CVE-2026-84308 | MEDIUM | 6.3 | phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplica… | 2026-09-01 |
| CVE-2026-84309 | NA | N/A | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cy… | 2026-09-01 |
| CVE-2026-63435 | MEDIUM | 5.3 | Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1… | 2026-09-01 |
| CVE-2026-71981 | HIGH | 8.8 | Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execu… | 2026-09-01 |
| CVE-2026-73524 | MEDIUM | 6.1 | Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote at… | 2026-09-01 |
| CVE-2026-73749 | CRITICAL | 9.8 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input… | 2026-09-01 |
| CVE-2026-73750 | HIGH | 8.8 | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. A… | 2026-09-01 |
| CVE-2026-73751 | HIGH | 8.8 | An authenticated user with low-privileged access could submit crafted input through the web-based management i… | 2026-09-01 |
| CVE-2026-73752 | HIGH | 8.8 | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploita… | 2026-09-01 |
| CVE-2026-73753 | HIGH | 8.8 | Exploitation through affected command-line operations could allow an authenticated low-privileged user to exec… | 2026-09-01 |
| CVE-2026-73754 | MEDIUM | 5.3 | Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could… | 2026-09-01 |
| CVE-2026-73755 | MEDIUM | 5.7 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow… | 2026-09-01 |
| CVE-2026-73756 | MEDIUM | 5.9 | A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive… | 2026-09-01 |
| CVE-2026-73757 | MEDIUM | 6.4 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker t… | 2026-09-01 |
| CVE-2026-73758 | MEDIUM | 6.5 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow… | 2026-09-01 |
| CVE-2026-73759 | MEDIUM | 6.5 | Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service… | 2026-09-01 |
| CVE-2026-73760 | MEDIUM | 6.5 | An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability … | 2026-09-01 |
| CVE-2026-73761 | MEDIUM | 6.5 | An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to una… | 2026-09-01 |
| CVE-2026-73762 | MEDIUM | 6.6 | A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumven… | 2026-09-01 |
| CVE-2026-73763 | HIGH | 7.1 | A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to exec… | 2026-09-01 |
| CVE-2026-73764 | HIGH | 7.1 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow a… | 2026-09-01 |
| CVE-2026-73765 | HIGH | 7.2 | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of thes… | 2026-09-01 |
| CVE-2026-73766 | HIGH | 7.2 | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker w… | 2026-09-01 |
| CVE-2026-73767 | HIGH | 7.2 | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful expl… | 2026-09-01 |
| CVE-2026-73768 | HIGH | 7.3 | A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malfo… | 2026-09-01 |
| CVE-2026-73770 | HIGH | 7.3 | An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an a… | 2026-09-01 |
| CVE-2026-73771 | HIGH | 7.5 | An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper auth… | 2026-09-01 |
| CVE-2026-73772 | MEDIUM | 6.5 | Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated… | 2026-09-01 |
| CVE-2026-73773 | HIGH | 7.5 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful expl… | 2026-09-01 |
| CVE-2026-73774 | HIGH | 7.6 | A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthe… | 2026-09-01 |
| CVE-2026-73775 | HIGH | 7.7 | Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges … | 2026-09-01 |
| CVE-2026-73776 | HIGH | 7.9 | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful explo… | 2026-09-01 |
| CVE-2026-73777 | HIGH | 8.1 | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an un… | 2026-09-01 |
| CVE-2026-73778 | HIGH | 8.1 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative acce… | 2026-09-01 |
| CVE-2026-73779 | HIGH | 8.2 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow a… | 2026-09-01 |
| CVE-2026-73780 | HIGH | 8.3 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cr… | 2026-09-01 |
| CVE-2026-73781 | HIGH | 8.4 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker t… | 2026-09-01 |
| CVE-2026-73782 | HIGH | 8.8 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticate… | 2026-09-01 |
| CVE-2026-73783 | MEDIUM | 4.9 | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an auth… | 2026-09-01 |
| CVE-2026-84287 | MEDIUM | 4.3 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionalit… | 2026-09-01 |
| CVE-2026-84310 | NA | N/A | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that cau… | 2026-09-01 |
| CVE-2026-84311 | NA | N/A | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that cau… | 2026-09-01 |
| CVE-2026-84361 | NA | N/A | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependenc… | 2026-09-01 |
| CVE-2026-84363 | MEDIUM | 5.9 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's … | 2026-09-01 |