Export limit exceeded: 385750 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385750 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72677 | 1 Elastic | 1 Kibana | 2026-09-02 | 7.3 High |
| Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed. | ||||
| CVE-2026-72675 | 1 Elastic | 1 Kibana | 2026-09-02 | 7.1 High |
| Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment. | ||||
| CVE-2026-72674 | 1 Elastic | 1 Kibana | 2026-09-02 | 6.5 Medium |
| Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated before it was used to assemble the response for each matching document. A single crafted request could therefore make Kibana build a response far larger than the data it was derived from, and the resulting processing and memory pressure exhausts the resources of the Kibana instance. | ||||
| CVE-2025-64649 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-02 | 5.9 Medium |
| IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. | ||||
| CVE-2026-34884 | 1 Apache | 1 Skywalking Mcp | 2026-09-02 | 9.8 Critical |
| SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | ||||
| CVE-2026-73702 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | 8.8 High |
| A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise. | ||||
| CVE-2026-73703 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | 8.8 High |
| A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | ||||
| CVE-2026-16821 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-09-02 | 7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability. | ||||
| CVE-2026-73704 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | 8.8 High |
| A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system. | ||||
| CVE-2026-84353 | 1 Google | 1 Chrome | 2026-09-02 | 9.6 Critical |
| Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-84352 | 1 Google | 1 Chrome | 2026-09-02 | 9.6 Critical |
| Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-84354 | 1 Google | 1 Chrome | 2026-09-02 | 9.6 Critical |
| Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-84324 | 1 Google | 1 Chrome | 2026-09-02 | 9 Critical |
| Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-84350 | 1 Google | 1 Chrome | 2026-09-02 | 8.8 High |
| Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low) | ||||
| CVE-2026-74927 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-09-02 | 5.3 Medium |
| The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications. | ||||
| CVE-2026-73705 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | 8.8 High |
| An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system. | ||||
| CVE-2026-84326 | 1 Google | 1 Chrome | 2026-09-02 | 8.8 High |
| Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-84335 | 1 Google | 1 Chrome | 2026-09-02 | 8.3 High |
| Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-84327 | 1 Google | 1 Chrome | 2026-09-02 | 6.5 Medium |
| Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-84331 | 1 Google | 1 Chrome | 2026-09-02 | 3.1 Low |
| Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||