CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78607
5.4 MEDIUM

Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges …

Sep 1, 2026
CVE-2026-78606
4.2 MEDIUM

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where …

Sep 1, 2026
CVE-2026-78605
5.9 MEDIUM

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment …

Sep 1, 2026
CVE-2026-78603
4.3 MEDIUM

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch …

Sep 1, 2026
CVE-2026-78597
4.3 MEDIUM

Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An …

Sep 1, 2026
CVE-2026-78592
7.3 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path …

Sep 1, 2026
CVE-2026-77223

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 1, 2026
CVE-2026-77222

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 1, 2026
CVE-2026-77221

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 1, 2026
CVE-2026-76658
10.0 CRITICAL

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access …

Sep 1, 2026
CVE-2026-76657
10.0 CRITICAL

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. …

Sep 1, 2026
CVE-2026-73748
2.2 LOW

A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. …

Sep 1, 2026
CVE-2026-73747
2.5 LOW

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access …

Sep 1, 2026
CVE-2026-73746
3.1 LOW

A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial …

Sep 1, 2026
CVE-2026-73745
3.1 LOW

A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected …

Sep 1, 2026
CVE-2026-73744
3.5 LOW

A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause …

Sep 1, 2026
CVE-2026-73743
3.7 LOW

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled …

Sep 1, 2026
CVE-2026-73742
4.3 MEDIUM

A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed …

Sep 1, 2026
CVE-2026-73741
4.3 MEDIUM

A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation …

Sep 1, 2026
CVE-2026-73740
4.4 MEDIUM

A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges …

Sep 1, 2026
CVE-2026-73739
4.4 MEDIUM

A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a …

Sep 1, 2026
CVE-2026-73738
4.7 MEDIUM

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view …

Sep 1, 2026
CVE-2026-73737
4.8 MEDIUM

An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate …

Sep 1, 2026
CVE-2026-73736
5.3 MEDIUM

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation …

Sep 1, 2026
CVE-2026-73735
5.4 MEDIUM

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. …

Sep 1, 2026
CVE-2026-73734
5.4 MEDIUM

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

Sep 1, 2026
CVE-2026-73733
5.4 MEDIUM

Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation …

Sep 1, 2026
CVE-2026-73732
5.6 MEDIUM

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to obtain …

Sep 1, 2026
CVE-2026-73731
6.1 MEDIUM

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) …

Sep 1, 2026
CVE-2026-73730
6.5 MEDIUM

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change …

Sep 1, 2026
CVE-2026-73729
6.5 MEDIUM

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream …

Sep 1, 2026
CVE-2026-73728
6.5 MEDIUM

Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of …

Sep 1, 2026
CVE-2026-73727
6.5 MEDIUM

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows …

Sep 1, 2026
CVE-2026-73726
6.8 MEDIUM

A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent …

Sep 1, 2026
CVE-2026-73725
7.0 HIGH

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary …

Sep 1, 2026
CVE-2026-73724
7.1 HIGH

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the …

Sep 1, 2026
CVE-2026-73723
7.1 HIGH

A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user …

Sep 1, 2026
CVE-2026-73722
7.2 HIGH

Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the …

Sep 1, 2026
CVE-2026-73721
7.2 HIGH

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric …

Sep 1, 2026
CVE-2026-73720
7.2 HIGH

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could …

Sep 1, 2026
CVE-2026-73719
7.2 HIGH

An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful …

Sep 1, 2026
CVE-2026-73718
7.4 HIGH

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker …

Sep 1, 2026
CVE-2026-73717
7.5 HIGH

A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary …

Sep 1, 2026
CVE-2026-73716
7.5 HIGH

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run …

Sep 1, 2026
CVE-2026-73715
7.5 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Sep 1, 2026
CVE-2026-73714
7.6 HIGH

A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to …

Sep 1, 2026
CVE-2026-73713
7.8 HIGH

Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code …

Sep 1, 2026
CVE-2026-73712
8.1 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if …

Sep 1, 2026
CVE-2026-73711
8.1 HIGH

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative …

Sep 1, 2026
CVE-2026-73710
8.2 HIGH

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.