Export limit exceeded: 403616 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403616 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403616 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70414 | 1 Dell | 1 Command|configure | 2026-10-09 | 5.5 Medium |
| Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | ||||
| CVE-2026-106439 | 1 Hydra-ecosystem | 1 Hydra | 2026-10-09 | 7.8 High |
| Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard through instantiate(), remove a denied target, and then invoke that target because sibling nodes are processed in insertion order against the same modified policy. The mutation persists in process-global state and can enable code execution with the application's privileges, while a narrow execution whitelist supplied by trusted Python code is not bypassed by the reported direct mutation path. This issue is fixed in versions 1.3.7 and 1.4.0.dev10. | ||||
| CVE-2026-82162 | 1 Dell | 1 Command|configure | 2026-10-09 | 7.4 High |
| Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||||
| CVE-2026-106440 | 1 Hydra-ecosystem | 1 Hydra | 2026-10-09 | 7.8 High |
| Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and does not apply the execution policy used by instantiate(), an attacker who controls Optuna sweep configuration or command-line overrides can select importable Python code for execution with the application's privileges, including bypassing a trusted execution whitelist on affected Hydra 1.4 development releases. This issue is fixed in versions 1.3.0 and 1.4.0.dev10. | ||||
| CVE-2026-106511 | 1 Multiversx Labs | 1 Multisig-improved | 2026-10-09 | 9.8 Critical |
| MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures. | ||||
| CVE-2026-103778 | 1 Dell | 1 Command|configure | 2026-10-09 | 6.2 Medium |
| Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2026-106441 | 1 Hydra-ecosystem | 1 Hydra | 2026-10-09 | 7.8 High |
| Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or factory and cause it to be invoked with the application's privileges, even in versions where instantiate() is protected because the logging path does not use instantiate(). This issue is fixed in versions 1.3.6 and 1.4.0.dev9. | ||||
| CVE-2026-106442 | 1 Hydra-ecosystem | 1 Hydra | 2026-10-09 | 7.8 High |
| Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure or defer the effective target and bypass name-based authorization. An attacker who causes an application to instantiate untrusted Hydra configuration can use these gaps to execute code with the application's privileges. This issue is fixed in versions 1.3.6 and 1.4.0.dev9. | ||||
| CVE-2026-76741 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 6.5 Medium |
| Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to cause a denial-of-service condition on the affected system. | ||||
| CVE-2026-76742 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.8 Critical |
| Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system. | ||||
| CVE-2026-76743 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.8 Critical |
| A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system. | ||||
| CVE-2026-76744 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.8 Critical |
| Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code. | ||||
| CVE-2026-76745 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.6 Critical |
| Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code. | ||||
| CVE-2026-78018 | 2026-10-09 | 6.3 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2026-78017 | 2026-10-09 | 3.8 Low | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass. | ||||
| CVE-2026-78016 | 2026-10-09 | 3.1 Low | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Validation of Specified Type of Input vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure and Information tampering. | ||||
| CVE-2026-76746 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.3 Critical |
| An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device. | ||||
| CVE-2026-76747 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 9.1 Critical |
| Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device. | ||||
| CVE-2026-76748 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 8.8 High |
| A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system. | ||||
| CVE-2026-76749 | 1 Hewlett Packard Enterprise (hpe) | 1 Aos-switch | 2026-10-09 | 6.5 Medium |
| A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information. | ||||