Total
13237 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19503 | 2026-08-28 | N/A | 4.8 MEDIUM | ||
| MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context. | |||||
| CVE-2026-20097 | 1 Cisco | 1 Unified Computing System | 2026-08-28 | N/A | 6.5 MEDIUM |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root. | |||||
| CVE-2026-21553 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-21552 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-21554 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-21548 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed. | |||||
| CVE-2026-21555 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-21550 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-21551 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-21549 | 2026-08-28 | N/A | 7.5 HIGH | ||
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | |||||
| CVE-2026-77543 | 2026-08-28 | N/A | 9.9 CRITICAL | ||
| A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |||||
| CVE-2026-77548 | 2026-08-28 | N/A | 9.9 CRITICAL | ||
| A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |||||
| CVE-2026-77546 | 2026-08-28 | N/A | 9.9 CRITICAL | ||
| A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |||||
| CVE-2026-77540 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | |||||
| CVE-2026-77539 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | |||||
| CVE-2026-77535 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device. | |||||
| CVE-2026-77542 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. | |||||
| CVE-2026-77552 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. | |||||
| CVE-2026-77554 | 2026-08-28 | N/A | 10.0 CRITICAL | ||
| A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. | |||||
| CVE-2026-77547 | 2026-08-28 | N/A | 9.9 CRITICAL | ||
| A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |||||
