Search

Search Results (403764 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-14123 2026-10-09 6.8 Medium
The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field.
CVE-2026-87110 1 Mongodb 1 Ops Manager 2026-10-09 5.3 Medium
An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.
CVE-2026-87109 1 Mongodb 1 Ops Manager 2026-10-09 5.3 Medium
An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
CVE-2026-107194 1 Sungrowpower 1 Isolarcloud 2026-10-09 N/A
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
CVE-2026-62179 1 Mervinpraison 1 Praisonai 2026-10-09 6.5 Medium
PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue.
CVE-2026-76458 1 Cisco 3 Cisco Nx-os System Software In Aci Mode, Nx-os Software, Unified Computing System Manager 2026-10-09 8.6 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76458 are related to improper handling of exceptional conditions issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
CVE-2026-76485 1 Cisco 1 Nx-os Software 2026-10-09 9.8 Critical
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.
CVE-2026-76488 1 Cisco 1 Application Policy Infrastructure Controller (apic) 2026-10-09 6.5 Medium
A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient access control to file system resources. An attacker could exploit this vulnerability by submitting crafted values in specific UI fields. A successful exploit could allow the attacker to access sensitive files from the underlying file system of an affected device, including key materials that could be used to elevate privileges to root on the affected APIC and on managed switches.
CVE-2026-76486 1 Cisco 1 Nx-os Software 2026-10-09 9.8 Critical
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.
CVE-2026-76499 1 Cisco 1 Application Policy Infrastructure Controller (apic) 2026-10-09 9.8 Critical
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76499 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.  
CVE-2026-76498 1 Cisco 1 Application Policy Infrastructure Controller (apic) 2026-10-09 9.8 Critical
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76498 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
CVE-2026-76500 1 Cisco 1 Application Policy Infrastructure Controller (apic) 2026-10-09 9.8 Critical
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-76500 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
CVE-2026-76501 1 Cisco 1 Nx-os Software 2026-10-09 9.8 Critical
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SRv6 features are enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.
CVE-2026-106164 1 Progress 1 Telerik Document Processing Libraries 2026-10-09 7.3 High
In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
CVE-2026-97714 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97714 is a is a vulnerability in the authentication sub-system of Secure Access servers prior to version 14.60. Attackers can send a malformed response during authentication and cause a persistent denial of service.
CVE-2026-107176 1 Redhat 2 Openshift, Openshift Container Platform 2026-10-09 6.8 Medium
A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grants get, list, and watch permissions on all Secret resources without resourceNames scoping. The operator only requires access to the pull-secret Secret. If the samples-operator pod or its service account token is compromised through a separate vulnerability, an attacker could read all secrets in openshift-config, potentially including OAuth identity provider credentials, cloud provider credentials, and other sensitive cluster configuration.
CVE-2026-97715 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97715 is a vulnerability in the client registration process of Secure Access servers prior to version 14.60. Authenticated attackers can pass malformed data to the server and cause a persistent denial of service.
CVE-2026-97716 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97716 is a vulnerability in the connection set up sub-system of Secure Access servers prior to version 14.60. Unauthenticated attackers can send specially crafted traffic to the server and cause a persistent denial of service.
CVE-2026-97717 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97717 is a vulnerability in the proxy sub-system of Secure Access servers prior to 14.60. Authenticated attackers can send malformed data to the server and cause a persistent denial of service.
CVE-2026-107227 1 Asynchttpclient Project 1 Async-http-client 2026-10-09 7.5 High
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.