Total
397360 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-82648 | 2026-09-02 | N/A | 7.1 HIGH | ||
| WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces. | |||||
| CVE-2026-82643 | 2026-09-02 | N/A | 6.5 MEDIUM | ||
| WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-factor confirmation emails and perform sustained password guessing attacks against user accounts. | |||||
| CVE-2026-82223 | 2026-09-02 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | |||||
| CVE-2026-81770 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | |||||
| CVE-2026-81288 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | |||||
| CVE-2026-73745 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 3.1 LOW |
| A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access when combined with other vulnerabilities. | |||||
| CVE-2026-73727 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 6.5 MEDIUM |
| Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer. | |||||
| CVE-2026-73726 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 6.8 MEDIUM |
| A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data. | |||||
| CVE-2026-73725 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.0 HIGH |
| A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host. | |||||
| CVE-2026-73724 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.1 HIGH |
| Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system. | |||||
| CVE-2026-73723 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.1 HIGH |
| A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform. | |||||
| CVE-2026-73722 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.2 HIGH |
| Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | |||||
| CVE-2026-73721 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.2 HIGH |
| Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host. | |||||
| CVE-2026-73720 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.2 HIGH |
| Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | |||||
| CVE-2026-73719 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.2 HIGH |
| An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system. | |||||
| CVE-2026-73718 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 7.4 HIGH |
| A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer. | |||||
| CVE-2026-73708 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 8.3 HIGH |
| A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system. | |||||
| CVE-2026-73707 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 8.5 HIGH |
| Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product. | |||||
| CVE-2026-73706 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 8.6 HIGH |
| A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service. | |||||
| CVE-2026-73705 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 8.8 HIGH |
| An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system. | |||||
