Export limit exceeded: 403698 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403698 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104944 1 Tp-link 1 Tapo C500 V2 2026-10-09 N/A
TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can cause an invalid indirect call, crashing the main service and resulting in a denial-of-service condition. Successful exploitation may allow an unauthenticated attacker with network access to the affected UDP service to repeatedly crash the TDP daemon, disrupting normal device operation and availability. No authentication, session establishment, or pairing is required to trigger the condition.
CVE-2026-104945 1 Tp-link 1 Tapo C500 V2 2026-10-09 N/A
TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-size stack arrays and resulting in a crash of the affected service. Successful exploitation may allow an authenticated attacker to cause the affected service to crash, resulting in a denial-of-service condition. Repeated exploitation may repeatedly disrupt camera management and PTZ-related functionality until the service recovers or restarts.
CVE-2026-70414 1 Dell 1 Command|configure 2026-10-09 5.5 Medium
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
CVE-2026-106439 1 Hydra-ecosystem 1 Hydra 2026-10-09 7.8 High
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard through instantiate(), remove a denied target, and then invoke that target because sibling nodes are processed in insertion order against the same modified policy. The mutation persists in process-global state and can enable code execution with the application's privileges, while a narrow execution whitelist supplied by trusted Python code is not bypassed by the reported direct mutation path. This issue is fixed in versions 1.3.7 and 1.4.0.dev10.
CVE-2026-82162 1 Dell 1 Command|configure 2026-10-09 7.4 High
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.
CVE-2026-106440 1 Hydra-ecosystem 1 Hydra 2026-10-09 7.8 High
Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and does not apply the execution policy used by instantiate(), an attacker who controls Optuna sweep configuration or command-line overrides can select importable Python code for execution with the application's privileges, including bypassing a trusted execution whitelist on affected Hydra 1.4 development releases. This issue is fixed in versions 1.3.0 and 1.4.0.dev10.
CVE-2026-106511 1 Multiversx Labs 1 Multisig-improved 2026-10-09 9.8 Critical
MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.
CVE-2026-103778 1 Dell 1 Command|configure 2026-10-09 6.2 Medium
Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2026-106441 1 Hydra-ecosystem 1 Hydra 2026-10-09 7.8 High
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or factory and cause it to be invoked with the application's privileges, even in versions where instantiate() is protected because the logging path does not use instantiate(). This issue is fixed in versions 1.3.6 and 1.4.0.dev9.
CVE-2026-106442 1 Hydra-ecosystem 1 Hydra 2026-10-09 7.8 High
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure or defer the effective target and bypass name-based authorization. An attacker who causes an application to instantiate untrusted Hydra configuration can use these gaps to execute code with the application's privileges. This issue is fixed in versions 1.3.6 and 1.4.0.dev9.
CVE-2026-76741 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 6.5 Medium
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to cause a denial-of-service condition on the affected system.
CVE-2026-76742 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.8 Critical
Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.
CVE-2026-76743 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.8 Critical
A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.
CVE-2026-76744 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.8 Critical
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.
CVE-2026-76745 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.6 Critical
Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.
CVE-2026-76746 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.3 Critical
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
CVE-2026-76747 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.1 Critical
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.
CVE-2026-76748 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 8.8 High
A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system.
CVE-2026-76749 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 6.5 Medium
A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information.
CVE-2026-76061 2 Cri-o, Redhat 3 Cri-o, Openshift, Openshift Container Platform 2026-10-09 5.5 Medium
A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.