Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-76468 — Cisco Meraki Hardening Release - Input Validation Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in …

meraki_mx_firmware | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-76467 — Cisco Meraki Software Hardening Release - Resource Lifetime Management Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in …

meraki_mx_firmware | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76465 — Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an u…

nx-os | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.6 CRITICAL
CVE-2026-76464 — Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in …

meraki_mx_firmware | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-76463 — Cisco Meraki Security Hardening Release: October 2026 - Improper Access Control Vulnerabi…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in …

meraki_mx_firmware | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-76459 — Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Write Vulne…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a sof…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.6 HIGH
CVE-2026-76458 — Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Handling of Exce…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a sof…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.6 HIGH
CVE-2026-76457 — Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Read Vulner…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a sof…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.6 HIGH
CVE-2026-76456 — Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Input Validation…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a sof…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76455 — Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control V…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a sof…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.1 CRITICAL
CVE-2026-76454 — Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to writ…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-76453 — Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Neutralization V…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a sof…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.9 MEDIUM
CVE-2026-76452 — Cisco Smart Software Manager On-Prem SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to conduct S…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.9 MEDIUM
CVE-2026-76437 — Cisco Smart Software Manager On-Prem Command Injection Vulnerability

A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to execute arbitra…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-62253 — Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == "…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-62252 — Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` a…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.1 HIGH
CVE-2026-62251 — Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/q…

Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlva…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.1 CRITICAL
CVE-2026-62176 — PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation

PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that i…

praisonai | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.2 HIGH
CVE-2026-20362 — Cisco Finesse Server-Side Request Forgery Vulnerability

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device…

finesse | Remote | Server-Side Request Forgery
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.1 CRITICAL
CVE-2026-20328 — Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain un…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15518 Results