0x04 // Actively Exploited
source: CISA KEV →
CVE
Vulnerability
EPSS
Added
CVE-2026-82078
PaperCut NG/MF Unsafe Reflection Vulnerability
PaperCut · NG/MF
<1%
Aug 31, 2026
CVE-2026-81578
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut · NG/MF
<1%
Aug 31, 2026
CVE-2023-49105
ownCloud Improper Authentication Vulnerability
ownCloud · ownCloud
43%
Aug 27, 2026
CVE-2026-53362
Linux Kernel Unspecified Vulnerability
Linux · Kernel
<1%
Aug 27, 2026
CVE-2026-66384
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog · Artifactory
<1%
Aug 27, 2026
CVE-2021-23758
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional · Ajax.NET Professional
84%
Aug 26, 2026
CVE-2015-3246
Red Hat Libuser Race Condition Vulnerability
Red Hat · Libuser
9%
Aug 26, 2026
CVE-2015-5287
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat · Automatic Bug Reporting Tool
5%
Aug 26, 2026
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
Linux · Kernel
10%
Aug 26, 2026
CVE-2026-8452
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix · NetScaler ADC and NetScaler Gateway
2%
Aug 26, 2026
0x03 // Latest CVEs
source: NVD · NIST →
Severity
CVE
CVSS
EPSS
Description
Published
MEDIUM
CVE-2026-84470
6.4
—
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bul…
Sep 1, 2026
MEDIUM
CVE-2026-84371
5.4
—
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer wi…
Sep 1, 2026
HIGH
CVE-2026-84370
8.2
—
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version…
Sep 1, 2026
MEDIUM
CVE-2026-84369
6.1
—
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version…
Sep 1, 2026
LOW
CVE-2026-84368
3.7
—
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/…
Sep 1, 2026
LOW
CVE-2026-84367
3.7
—
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/…
Sep 1, 2026
HIGH
CVE-2026-84366
7.4
—
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handle…
Sep 1, 2026
MEDIUM
CVE-2026-84365
6.5
—
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix…
Sep 1, 2026
MEDIUM
CVE-2026-84364
5.3
—
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody()…
Sep 1, 2026
MEDIUM
CVE-2026-84363
5.9
—
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query help…
Sep 1, 2026
N/A
CVE-2026-84361
—
—
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package…
Sep 1, 2026
N/A
CVE-2026-84311
—
—
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/…
Sep 1, 2026
N/A
CVE-2026-84310
—
—
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/…
Sep 1, 2026
MEDIUM
CVE-2026-84287
4.3
—
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the f…
Sep 1, 2026
MEDIUM
CVE-2026-73783
4.9
—
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated…
Sep 1, 2026
HIGH
CVE-2026-73782
8.8
—
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote c…
Sep 1, 2026
HIGH
CVE-2026-73781
8.4
—
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct…
Sep 1, 2026
HIGH
CVE-2026-73780
8.3
—
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site R…
Sep 1, 2026
HIGH
CVE-2026-73779
8.2
—
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthen…
Sep 1, 2026
HIGH
CVE-2026-73778
8.1
—
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An una…
Sep 1, 2026
HIGH
CVE-2026-73777
8.1
—
Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthentica…
Sep 1, 2026
HIGH
CVE-2026-73776
7.9
—
A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation co…
Sep 1, 2026
HIGH
CVE-2026-73775
7.7
—
Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access…
Sep 1, 2026
HIGH
CVE-2026-73774
7.6
—
A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated d…
Sep 1, 2026
HIGH
CVE-2026-73773
7.5
—
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation o…
Sep 1, 2026
MEDIUM
CVE-2026-73772
6.5
—
Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of…
Sep 1, 2026
HIGH
CVE-2026-73771
7.5
—
An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication…
Sep 1, 2026
HIGH
CVE-2026-73770
7.3
—
An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticat…
Sep 1, 2026
HIGH
CVE-2026-73768
7.3
—
A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input…
Sep 1, 2026
HIGH
CVE-2026-73767
7.2
—
Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation o…
Sep 1, 2026
HIGH
CVE-2026-73766
7.2
—
Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with admini…
Sep 1, 2026
HIGH
CVE-2026-73765
7.2
—
Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerab…
Sep 1, 2026
HIGH
CVE-2026-73764
7.1
—
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthen…
Sep 1, 2026
HIGH
CVE-2026-73763
7.1
—
A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitr…
Sep 1, 2026
MEDIUM
CVE-2026-73762
6.6
—
A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing…
Sep 1, 2026
MEDIUM
CVE-2026-73761
6.5
—
An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticat…
Sep 1, 2026
MEDIUM
CVE-2026-73760
6.5
—
An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an…
Sep 1, 2026
MEDIUM
CVE-2026-73759
6.5
—
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition…
Sep 1, 2026
MEDIUM
CVE-2026-73758
6.5
—
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authen…
Sep 1, 2026
MEDIUM
CVE-2026-73757
6.4
—
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct…
Sep 1, 2026
MEDIUM
CVE-2026-73756
5.9
—
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive informati…
Sep 1, 2026
MEDIUM
CVE-2026-73755
5.7
—
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authen…
Sep 1, 2026
MEDIUM
CVE-2026-73754
5.3
—
Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an…
Sep 1, 2026
HIGH
CVE-2026-73753
8.8
—
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitr…
Sep 1, 2026
HIGH
CVE-2026-73752
8.8
—
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of th…
Sep 1, 2026
HIGH
CVE-2026-73751
8.8
—
An authenticated user with low-privileged access could submit crafted input through the web-based management interface t…
Sep 1, 2026
HIGH
CVE-2026-73750
8.8
—
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenti…
Sep 1, 2026
CRITICAL
CVE-2026-73749
9.8
—
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unaut…
Sep 1, 2026
MEDIUM
CVE-2026-73524
6.1
—
Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to…
Sep 1, 2026
HIGH
CVE-2026-71981
8.8
—
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitra…
Sep 1, 2026
MEDIUM
CVE-2026-63435
5.3
—
Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Ut…
Sep 1, 2026
N/A
CVE-2026-84309
—
—
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree…
Sep 1, 2026
MEDIUM
CVE-2026-84308
6.3
—
phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in ph…
Sep 1, 2026
LOW
CVE-2026-84307
3.7
—
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5…
Sep 1, 2026
MEDIUM
CVE-2026-78608
6.5
—
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authori…
Sep 1, 2026
MEDIUM
CVE-2026-78607
5.4
—
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Pri…
Sep 1, 2026
MEDIUM
CVE-2026-78606
4.2
—
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via…
Sep 1, 2026
MEDIUM
CVE-2026-78605
5.9
—
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to informati…
Sep 1, 2026
MEDIUM
CVE-2026-78603
4.3
—
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Acces…
Sep 1, 2026
MEDIUM
CVE-2026-78597
4.3
—
Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Acce…
Sep 1, 2026
HIGH
CVE-2026-78592
7.3
—
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauth…
Sep 1, 2026
CRITICAL
CVE-2026-76658
10.0
—
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthentica…
Sep 1, 2026
CRITICAL
CVE-2026-76657
10.0
—
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauth…
Sep 1, 2026
LOW
CVE-2026-73748
2.2
—
A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privi…
Sep 1, 2026
LOW
CVE-2026-73747
2.5
—
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitatio…
Sep 1, 2026
LOW
CVE-2026-73746
3.1
—
A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated…
Sep 1, 2026
LOW
CVE-2026-73745
3.1
—
A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to…
Sep 1, 2026
LOW
CVE-2026-73744
3.5
—
A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that co…
Sep 1, 2026
LOW
CVE-2026-73743
3.7
—
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r…
Sep 1, 2026
MEDIUM
CVE-2026-73742
4.3
—
A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator…
Sep 1, 2026
MEDIUM
CVE-2026-73741
4.3
—
A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to…
Sep 1, 2026
MEDIUM
CVE-2026-73740
4.4
—
A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged use…
Sep 1, 2026
MEDIUM
CVE-2026-73739
4.4
—
A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative priv…
Sep 1, 2026
MEDIUM
CVE-2026-73738
4.7
—
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low pr…
Sep 1, 2026
MEDIUM
CVE-2026-73737
4.8
—
An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful…
Sep 1, 2026
MEDIUM
CVE-2026-73736
5.3
—
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r…
Sep 1, 2026
MEDIUM
CVE-2026-73735
5.4
—
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to…
Sep 1, 2026
MEDIUM
CVE-2026-73734
5.4
—
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r…
Sep 1, 2026
MEDIUM
CVE-2026-73733
5.4
—
Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator…
Sep 1, 2026
MEDIUM
CVE-2026-73732
5.6
—
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low pr…
Sep 1, 2026
MEDIUM
CVE-2026-73731
6.1
—
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r…
Sep 1, 2026
MEDIUM
CVE-2026-73730
6.5
—
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could…
Sep 1, 2026
MEDIUM
CVE-2026-73729
6.5
—
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low pr…
Sep 1, 2026
MEDIUM
CVE-2026-73728
6.5
—
Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated l…
Sep 1, 2026
MEDIUM
CVE-2026-73727
6.5
—
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to…
Sep 1, 2026
MEDIUM
CVE-2026-73726
6.8
—
A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could pote…
Sep 1, 2026
HIGH
CVE-2026-73725
7.0
—
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitatio…
Sep 1, 2026
HIGH
CVE-2026-73724
7.1
—
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could a…
Sep 1, 2026
HIGH
CVE-2026-73723
7.1
—
A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Suc…
Sep 1, 2026
HIGH
CVE-2026-73722
7.2
—
Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an…
Sep 1, 2026
HIGH
CVE-2026-73721
7.2
—
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL…
Sep 1, 2026
HIGH
CVE-2026-73720
7.2
—
Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to ac…
Sep 1, 2026
HIGH
CVE-2026-73719
7.2
—
An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticat…
Sep 1, 2026
HIGH
CVE-2026-73718
7.4
—
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r…
Sep 1, 2026
HIGH
CVE-2026-73717
7.5
—
A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that co…
Sep 1, 2026
HIGH
CVE-2026-73716
7.5
—
A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that c…
Sep 1, 2026
HIGH
CVE-2026-73715
7.5
—
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a…
Sep 1, 2026
HIGH
CVE-2026-73714
7.6
—
A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploit…
Sep 1, 2026
HIGH
CVE-2026-73713
7.8
—
Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitati…
Sep 1, 2026
HIGH
CVE-2026-73712
8.1
—
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbit…
Sep 1, 2026
No CVEs match your filter.