Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-100293 — Improper verification of cryptographic signature in Anjvision YSSD-RTMP-H5

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design al…

Remote | Supply Chain
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-100292 — Improper neutralization of special elements used in an OS command ('OS command injection'…

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active…

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-100291 — Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.3 HIGH
CVE-2026-96274 — Uncaught exception in Baicells Nova 430H

In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not prope…

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
2.7 LOW
CVE-2026-76738 — Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant…

A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Success…

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.0 LOW
CVE-2026-76737 — Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networ…

An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a…

| Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.3 LOW
CVE-2026-76736 — Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Netwo…

A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt t…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.1 MEDIUM
CVE-2026-76735 — Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On

A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high …

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.8 MEDIUM
CVE-2026-76734 — Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Network…

A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.9 MEDIUM
CVE-2026-76733 — Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint

A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Succe…

Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.4 MEDIUM
CVE-2026-76732 — Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Inst…

A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achie…

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-76731 — Authentication Bypass in the Captive Portal of HPE Networking Instant On

An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exp…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-76730 — Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON A…

An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication control…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.6 MEDIUM
CVE-2026-76729 — Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Inst…

A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.2 HIGH
CVE-2026-76728 — Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Network…

A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successf…

Remote | Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.2 HIGH
CVE-2026-76727 — Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON

Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Suc…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.1 HIGH
CVE-2026-76726 — Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON…

An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outsi…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.6 CRITICAL
CVE-2026-76725 — Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs

A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Suc…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.6 CRITICAL
CVE-2026-76724 — Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs…

A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially c…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.6 CRITICAL
CVE-2026-76723 — Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in…

Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exp…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14618 Results