Vulnerabilities

Summary — last 7 days

New vulnerabilities2,678▼ 660 vs. last week
Critical / high1,266▼ 293 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)250▼ 252 vs. last week
–

468 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedMedium (6.8)——Brocade Fabric OSAI10/8/202610/8/2026
A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol component of Brocade Fabric OS versions before 10.0.1. While this code path is part of internal diagnostic functionality and is not directly accessible via…
ReceivedHigh (7.5)——Brocade Fabric OSAI10/8/202610/8/2026
Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or…
ReceivedMedium (5.3)——Brocade Fabric OSAI10/8/202610/8/2026
An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer…
ReceivedHigh (8.7)——Brocade FabricAI10/8/202610/8/2026
A stack-based buffer overflow vulnerability exists in the SNMP daemon request handling of Brocade Fabric versions before 10.0.1. When processing an incoming SNMPv3 packet, an internal statistics gathering handler copies user-supplied context name data into a fixed-size buffer without properly validating the length of…
ReceivedMedium (6.9)——Brocade Fabric OSAI10/8/202610/8/2026
An input validation and output encoding vulnerability exists in the web management interface of Brocade Fabric OS versions before 10.0.1. When configuring Federated Authentication (FA), the system fails to sanitize the Identity Provider (IdP) issuer parameter. An authenticated administrator—or an attacker capable of…
ReceivedMedium (6.9)——Brocade Fabric OSAI10/8/202610/8/2026
A stack-based buffer overflow vulnerability exists in the security library component of Brocade Fabric OS versions before 10.0.1. When parsing uploaded X.509 PEM certificates for management display, the system improperly validates the length of the Authority Key Identifier (AKI) extension before copying string tokens…
ReceivedMedium (6.8)——Brocade Fabric OSAI10/8/202610/8/2026
An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full proxy URL. Anyone with access to the diagnostic support bundle, such as support…
ReceivedHigh (7.1)——Brocade Fabric OSAI10/8/202610/8/2026
An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit…
ReceivedMedium (5.1)——Brocade Fabric OSAI10/8/202610/8/2026
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized…
ReceivedMedium (5.1)——Brocade Fabric OSAI10/8/202610/8/2026
A missing authorization check in Brocade Fabric OS versions before 10.0.1 REST API interface of affected platform releases allows an authenticated user, regardless of their assigned role or administrative scope, to retrieve complete Monitoring and Alerting Policy Suite (MAPS) violation data across all logical…
ReceivedMedium (6.9)——Brocade Fabric OSAI10/8/202610/8/2026
A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum…
ReceivedMedium (6)——Brocade Fabric OSAI10/8/202610/8/2026
A stack-based buffer overflow vulnerability exists in the Internet Key Exchange (IKEv2) protocol handler on Brocade Fabric OS versions before 10.0.1. The vulnerability occurs when processing initial IKE key exchange requests on extension switches or blades running IPsec-enabled Fibre Channel over IP (FCIP) circuits.…
ReceivedHigh (7.1)——Brocade Fabric OSAI10/8/202610/8/2026
A critical authorization bypass vulnerability exists in the Management Server handling of Brocade Fabric OS versions before 10.0.1. A compromised switch connected to the fabric can transmit crafted inband Fibre Channel vendor-unique CT (Common Transport) management requests to bypass administrative authentication.…
ReceivedHigh (8.6)——Brocade Fabric OSAI10/8/202610/8/2026
Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts…
ReceivedHigh (8.6)——Brocade Fabric OSAI10/8/202610/8/2026
Multiple OS Command Injection vulnerabilities exist in the management interface and session processing routines of Brocade Fabric OS versions before 10.0.1. Input processing flaws during remote management connection validation and session verification for directory-based user accounts allow untrusted input containing…
ReceivedHigh (7.1)——Brocade Fabric OSAI10/7/202610/7/2026
An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows…
ReceivedHigh (8.5)——Brocade Fabric OSAI10/7/202610/7/2026
A command injection vulnerability in the REST API management interface of Brocade Fabric OS versions before 10.0.1 allows an authenticated user to execute arbitrary system commands via crafted input parameters.
ReceivedHigh (8.5)——Brocade Fabric OSAI10/7/202610/7/2026
When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable number of elements. An authenticated administrator can exploit this vulnerability…
AnalyzedCritical (10)0.90%—Microsoft Fabric9/17/20269/25/2026
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
Undergoing AnalysisLow (3.5)0.24%—Dell Smartfabric ManagerAI9/17/20269/18/2026
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Undergoing AnalysisHigh (8.1)0.20%—Dell Smartfabric ManagerAI9/17/20269/18/2026
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Awaiting AnalysisMedium (4)0.12%—Fabricjs Fabric.jsAI9/15/20269/18/2026
Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The…
Awaiting AnalysisCritical (9.1)0.30%—Dell Smartfabric Os10AI9/15/20269/16/2026
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Awaiting AnalysisCritical (9.8)0.50%—Dell Smartfabric Os10AI9/15/20269/16/2026
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
Awaiting AnalysisMedium (6.3)0.45%—Hyperledger Fabric CAAI9/15/20269/30/2026
Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated…
Orbitaley — Vulnerabilities