Vulnerabilities (CVE)

Total 403599 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-63457 1 Hpe 2 Integrated Lights-out 6, Integrated Lights-out 6 Firmware 2026-08-10 N/A 6.5 MEDIUM
A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
CVE-2026-17617 1 Ibm 1 Application Gateway Operator 2026-08-10 N/A 8.5 HIGH
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
CVE-2026-13477 1 Ibm 1 Qradar Security Information And Event Manager 2026-08-10 N/A 4.7 MEDIUM
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
CVE-2026-46581 1 Eclipse 1 Mojarra 2026-08-10 N/A 7.5 HIGH
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.
CVE-2026-6788 1 Watchguard 1 Agent 2026-08-10 N/A 7.8 HIGH
Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.
CVE-2026-6787 1 Watchguard 1 Agent 2026-08-10 N/A 7.8 HIGH
Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.
CVE-2026-41288 1 Watchguard 1 Agent 2026-08-10 N/A 7.8 HIGH
Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.
CVE-2026-41287 1 Watchguard 1 Agent 2026-08-10 N/A 6.5 MEDIUM
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.
CVE-2026-41286 1 Watchguard 1 Agent 2026-08-10 N/A 6.5 MEDIUM
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.
CVE-2026-40512 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-3344 1 Watchguard 39 Firebox M270, Firebox M290, Firebox M295 and 36 more 2026-08-10 N/A 4.9 MEDIUM
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.
CVE-2026-3343 1 Watchguard 37 Firebox M270, Firebox M290, Firebox M295 and 34 more 2026-08-10 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.
CVE-2026-35028 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35027 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35026 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35006 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35005 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34423 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29517 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29033 2026-08-10 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.