Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-76752 — Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Un…

Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote at…

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-76751 — Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Un…

A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary co…

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-76750 — Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web…

Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to exec…

Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-76749 — Unauthenticated Sensitive Information Disclosure in AOS-S

A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information.

Remote | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.8 HIGH
CVE-2026-76748 — Authenticated Privilege Escalation Vulnerability in the API of AOS-S

A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the…

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.1 CRITICAL
CVE-2026-76747 — Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S

Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial…

Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.3 CRITICAL
CVE-2026-76746 — Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure …

An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of se…

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.6 CRITICAL
CVE-2026-76745 — Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Executi…

Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-76744 — Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S

Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.

Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-76743 — Authentication Bypass Vulnerability in the Management Interface of AOS-S

A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain pre…

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-76742 — Authentication Bypass in the Web Management Interface of AOS-S

Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affecte…

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-76741 — Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S

Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to cause a denial-of-service condition on the affected s…

Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.5 MEDIUM
CVE-2026-76061 — Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass

A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) h…

openshift_container_platform | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-73278 — Gitea WebAuthn bypass during OAuth and OIDC sign-in

Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected ext…

gitea | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-70357 — Gitea repository migration SSRF through DNS rebinding

Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker …

gitea | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-106454 — Twisted: IMAP wildcardToRegexp() ReDoS

Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegexp() in twisted/mail/imap4.py translates the IMAP asterisk and percent wild…

twisted | Remote | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106453 — yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte…

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compre…

Remote | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106452 — yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the …

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but …

Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.3 HIGH
CVE-2026-106451 — yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable …

yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-l…

| Race Condition
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106450 — yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing …

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header i…

Remote | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 15427 Results