CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-73721
7.2 HIGH

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric …

Sep 1, 2026
CVE-2026-73720
7.2 HIGH

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could …

Sep 1, 2026
CVE-2026-73719
7.2 HIGH

An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful …

Sep 1, 2026
CVE-2026-73718
7.4 HIGH

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker …

Sep 1, 2026
CVE-2026-73717
7.5 HIGH

A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary …

Sep 1, 2026
CVE-2026-73716
7.5 HIGH

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run …

Sep 1, 2026
CVE-2026-73715
7.5 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Sep 1, 2026
CVE-2026-73714
7.6 HIGH

A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to …

Sep 1, 2026
CVE-2026-73713
7.8 HIGH

Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code …

Sep 1, 2026
CVE-2026-73712
8.1 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if …

Sep 1, 2026
CVE-2026-73711
8.1 HIGH

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative …

Sep 1, 2026
CVE-2026-73710
8.2 HIGH

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Sep 1, 2026
CVE-2026-73709
8.3 HIGH

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying …

Sep 1, 2026
CVE-2026-73708
8.3 HIGH

A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain …

Sep 1, 2026
CVE-2026-73707
8.5 HIGH

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing …

Sep 1, 2026
CVE-2026-73706
8.6 HIGH

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the …

Sep 1, 2026
CVE-2026-73705
8.8 HIGH

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful …

Sep 1, 2026
CVE-2026-73704
8.8 HIGH

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate …

Sep 1, 2026
CVE-2026-73703
8.8 HIGH

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) …

Sep 1, 2026
CVE-2026-73702
8.8 HIGH

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate …

Sep 1, 2026
CVE-2026-72649
8.8 HIGH

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained …

Sep 1, 2026
CVE-2026-63137
8.3 HIGH

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions …

Sep 1, 2026
CVE-2026-45221
7.8 HIGH

Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files …

Sep 1, 2026
CVE-2026-8712
8.3 HIGH

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying …

Sep 1, 2026
CVE-2026-83551
7.2 HIGH

Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an …

Sep 1, 2026
CVE-2026-52130
7.5 HIGH

llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.

Sep 1, 2026
CVE-2026-58566
8.8 HIGH

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Sep 1, 2026
CVE-2026-84268
8.8 HIGH

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() …

Sep 1, 2026
CVE-2026-84203
8.1 HIGH

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with …

Sep 1, 2026
CVE-2026-84202
8.8 HIGH

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories …

Sep 1, 2026
CVE-2026-84201
7.1 HIGH

appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT …

Sep 1, 2026
CVE-2026-79682
8.8 HIGH

Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Sep 1, 2026
CVE-2026-61779
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61778
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61777
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61776
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61775
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61774
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61773
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61772
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61771
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61770
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61769
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61768
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61767
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61766
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61765
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61764
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61763
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61762
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.