Export limit exceeded: 403616 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403616 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403616 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403616 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20328 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 9.1 Critical |
| A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application. This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface. A successful exploit could allow the attacker to reset the password of an arbitrary account, including high-privileged administrative user accounts, possibly allowing the attacker to gain unauthorized access to the application as any user. | ||||
| CVE-2026-76452 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 4.9 Medium |
| A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to conduct SQL injection attacks against an affected application. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read additional contents of the internal database of an affected application that should not normally be accessible to administrative users, thus impacting system confidentiality. To exploit this vulnerability, the attacker must have valid administrative user credentials on the affected application. | ||||
| CVE-2026-76437 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 4.9 Medium |
| A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user-supplied content within configurations that are submitted to the web-based management interface. An attacker could exploit this vulnerability by updating configurations within the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials. Because only an attacker who already holds system administrator privileges can exploit the vulnerability, the only additional privileges gained include the ability to turn off the system, which an administrative user could not normally do. | ||||
| CVE-2026-76454 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 9.1 Critical |
| A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition. | ||||
| CVE-2026-62252 | 1 Sipcapture | 1 Homer | 2026-10-09 | 9.8 Critical |
| Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue. | ||||
| CVE-2026-101886 | 1 Cisco | 1 Jabber For Android | 2026-10-09 | 4 Medium |
| Cisco Jabber for Android (com.cisco.im) before 15.3.1.311364 contains a path traversal vulnerability that allows a malicious app with no permissions to write attacker-controlled files into Jabber's private data directory by exploiting the exported crosslaunch.share activity and an unsanitized display name from a ContentProvider used in file path construction. Attackers can craft a shared content:// URI with a display name containing '../' sequences to place fully attacker-controlled content within directories such as databases/, shared_prefs/, no_backup/, and files/ without user interaction. | ||||
| CVE-2026-76480 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 9.8 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76480 are related to issues with improper authentication that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-306. | ||||
| CVE-2026-76482 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 10 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76482 are related to issues with improper input verification that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-347. | ||||
| CVE-2026-76483 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 9.1 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76483 are related to issues with insufficiently protected credentials that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-522. | ||||
| CVE-2026-76484 | 1 Cisco | 1 Cisco License On-prem | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76484 are related to issues with insufficient protection against code injection that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-94. | ||||
| CVE-2026-76463 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | ||||
| CVE-2026-76464 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 9.6 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119. | ||||
| CVE-2026-76468 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.2 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. | ||||
| CVE-2026-76469 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 7.4 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76469 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691. | ||||
| CVE-2026-76470 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. | ||||
| CVE-2026-76467 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 7.5 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | ||||
| CVE-2026-76472 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74. | ||||
| CVE-2026-106557 | 1 Backstage | 2 Backstage, Plugin-techdocs-node | 2026-10-09 | 7.7 High |
| Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later. | ||||
| CVE-2026-92542 | 2 Docker, Moby | 3 Docker Engine, Docker Engine Overlay Network Driver, Moby Overlay Network Driver | 2026-10-09 | 7.1 High |
| The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to | ||||
| CVE-2026-94662 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-09 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19. | ||||