Export limit exceeded: 385985 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385985 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76658 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 10 Critical |
| A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise. | ||||
| CVE-2026-63435 | 1 Mikel | 1 Mail | 2026-09-02 | 5.3 Medium |
| Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy charset capture to decode only the first RFC 2047 encoded-word and mishandle surrounding or subsequent text. A crafted malformed encoded-word in an address display name or local part could cross ? delimiters and make decoded From, To, or Reply-To header values differ from the raw values inspected by a human reviewer or downstream parser, enabling apparent sender or recipient spoofing, phishing, or authorization-check bypass. This issue is fixed in version 2.9.1. | ||||
| CVE-2026-73749 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 9.8 Critical |
| Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges. | ||||
| CVE-2026-73750 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 8.8 High |
| Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. | ||||
| CVE-2026-73751 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 8.8 High |
| An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. | ||||
| CVE-2026-73752 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 8.8 High |
| An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. | ||||
| CVE-2026-73753 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 8.8 High |
| Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. | ||||
| CVE-2026-73754 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 5.3 Medium |
| Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system. | ||||
| CVE-2026-73755 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 5.7 Medium |
| A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system. | ||||
| CVE-2026-73756 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 5.9 Medium |
| A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system. | ||||
| CVE-2026-73757 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 6.4 Medium |
| A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information. | ||||
| CVE-2026-73758 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 6.5 Medium |
| A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system. | ||||
| CVE-2026-73759 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 6.5 Medium |
| Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices. | ||||
| CVE-2026-73760 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 6.5 Medium |
| An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files. | ||||
| CVE-2026-73761 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 6.5 Medium |
| An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system. | ||||
| CVE-2026-73762 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 6.6 Medium |
| A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy. | ||||
| CVE-2026-73763 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 7.1 High |
| A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility. | ||||
| CVE-2026-73764 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 7.1 High |
| Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services. | ||||
| CVE-2026-73765 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 7.2 High |
| Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. | ||||
| CVE-2026-73766 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-cx | 2026-09-02 | 7.2 High |
| Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||||