CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84367
3.7 LOW

joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits …

Sep 1, 2026
CVE-2026-84366
7.4 HIGH

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request …

Sep 1, 2026
CVE-2026-84365
6.5 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover …

Sep 1, 2026
CVE-2026-84364
5.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested …

Sep 1, 2026
CVE-2026-84363
5.9 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a …

Sep 1, 2026
CVE-2026-84361

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or …

Sep 1, 2026
CVE-2026-84311

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to …

Sep 1, 2026
CVE-2026-84310

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long …

Sep 1, 2026
CVE-2026-84287
4.3 MEDIUM

A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session …

Sep 1, 2026
CVE-2026-73783
4.9 MEDIUM

Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the …

Sep 1, 2026
CVE-2026-73782
8.8 HIGH

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability …

Sep 1, 2026
CVE-2026-73781
8.4 HIGH

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an …

Sep 1, 2026
CVE-2026-73780
8.3 HIGH

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow …

Sep 1, 2026
CVE-2026-73779
8.2 HIGH

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful …

Sep 1, 2026
CVE-2026-73778
8.1 HIGH

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a …

Sep 1, 2026
CVE-2026-73777
8.1 HIGH

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

Sep 1, 2026
CVE-2026-73776
7.9 HIGH

A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to …

Sep 1, 2026
CVE-2026-73775
7.7 HIGH

Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an …

Sep 1, 2026
CVE-2026-73774
7.6 HIGH

A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted …

Sep 1, 2026
CVE-2026-73773
7.5 HIGH

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal …

Sep 1, 2026
CVE-2026-73772
6.5 MEDIUM

Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the …

Sep 1, 2026
CVE-2026-73771
7.5 HIGH

An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability …

Sep 1, 2026
CVE-2026-73770
7.3 HIGH

An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and …

Sep 1, 2026
CVE-2026-73768
7.3 HIGH

A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the …

Sep 1, 2026
CVE-2026-73767
7.2 HIGH

Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands …

Sep 1, 2026
CVE-2026-73766
7.2 HIGH

Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could …

Sep 1, 2026
CVE-2026-73765
7.2 HIGH

Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying …

Sep 1, 2026
CVE-2026-73764
7.1 HIGH

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In …

Sep 1, 2026
CVE-2026-73763
7.1 HIGH

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution …

Sep 1, 2026
CVE-2026-73762
6.6 MEDIUM

A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases …

Sep 1, 2026
CVE-2026-73761
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. …

Sep 1, 2026
CVE-2026-73760
6.5 MEDIUM

An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface …

Sep 1, 2026
CVE-2026-73759
6.5 MEDIUM

Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities …

Sep 1, 2026
CVE-2026-73758
6.5 MEDIUM

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state …

Sep 1, 2026
CVE-2026-73757
6.4 MEDIUM

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful …

Sep 1, 2026
CVE-2026-73756
5.9 MEDIUM

A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows …

Sep 1, 2026
CVE-2026-73755
5.7 MEDIUM

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, …

Sep 1, 2026
CVE-2026-73754
5.3 MEDIUM

Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable …

Sep 1, 2026
CVE-2026-73753
8.8 HIGH

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Sep 1, 2026
CVE-2026-73752
8.8 HIGH

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files …

Sep 1, 2026
CVE-2026-73751
8.8 HIGH

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

Sep 1, 2026
CVE-2026-73750
8.8 HIGH

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially …

Sep 1, 2026
CVE-2026-73749
9.8 CRITICAL

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities …

Sep 1, 2026
CVE-2026-73524
6.1 MEDIUM

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads …

Sep 1, 2026
CVE-2026-71981
8.8 HIGH

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object …

Sep 1, 2026
CVE-2026-63435
5.3 MEDIUM

Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match …

Sep 1, 2026
CVE-2026-84309

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child …

Sep 1, 2026
CVE-2026-84308
6.3 MEDIUM

phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() …

Sep 1, 2026
CVE-2026-84307
3.7 LOW

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating …

Sep 1, 2026
CVE-2026-78608
6.5 MEDIUM

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.