Vulnerabilities
Summary — last 7 days
New vulnerabilities2,532▼ 361 vs. last week
Critical / high1,338▲ 69 vs. last week
New active exploitation (KEV)6▼ 6 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
244 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Critical (9.3) | 0.59% | — | H3C CVMAI | 10/2/2026 | 10/2/2026 | H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path… | |
| Awaiting Analysis | High (8.1) | 0.39% | — | Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI | 9/15/2026 | 9/18/2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant… | |
| Awaiting Analysis | High (8.8) | 0.27% | — | Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI | 9/15/2026 | 9/18/2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack,… | |
| Deferred | High (7.3) | 3.8% | — | H3C Nx15AI | 8/5/2026 | 8/12/2026 | A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may… | |
| Deferred | High (7.3) | 0.85% | — | H3C Nx15AI | 8/5/2026 | 8/12/2026 | A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Deferred | High (7.3) | 3.8% | — | H3C Nx15AI | 8/5/2026 | 8/12/2026 | A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Deferred | High (7.3) | 3.6% | — | H3C Nx15AI | 8/4/2026 | 8/12/2026 | A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure. | |
| Deferred | High (7.3) | 3.6% | — | H3C Nx15AI | 8/4/2026 | 8/12/2026 | A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early… | |
| Deferred | High (7.3) | 3.6% | — | H3C Nx15AI | 8/4/2026 | 8/12/2026 | A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted… | |
| Deferred | High (7.3) | 3.6% | — | H3C Nx15AI | 8/4/2026 | 8/12/2026 | A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted… | |
| Deferred | Medium (6.9) | 0.65% | — | H3C Nx15AI | 8/4/2026 | 8/12/2026 | A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure. | |
| Deferred | Critical (9.8) | 2.3% | — | H3C Magic Be18000AIH3C Nx400AIH3C Magic Nx30 PROAIH3C Magic R3010AI+4 | 8/4/2026 | 10/1/2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object… | |
| Deferred | Medium (5.5) | 0.41% | — | H3C Secpath F1000-c8300AI | 7/16/2026 | 7/16/2026 | A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor… | |
| Deferred | Medium (5.5) | 0.47% | — | H3C Nx15AI | 7/12/2026 | 7/14/2026 | A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The… | |
| Deferred | High (7.4) | 0.48% | — | H3C Magic B0AI | 6/1/2026 | 7/22/2026 | A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Deferred | High (7.4) | 0.80% | — | H3C Magic B0AI | 5/24/2026 | 7/23/2026 | A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was… | |
| Deferred | High (7.3) | 0.85% | — | H3C Magic B3AI | 5/17/2026 | 6/17/2026 | A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor… | |
| Deferred | High (7.4) | 0.80% | — | H3C Magic B1AI | 4/19/2026 | 6/17/2026 | A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Deferred | High (7.4) | 0.80% | — | H3C Magic B1AI | 4/19/2026 | 6/17/2026 | A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Deferred | High (7.4) | 0.80% | — | H3C Magic B0AI | 4/19/2026 | 6/17/2026 | A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.… | |
| Deferred | Medium (5.5) | 4.6% | — | H3C Acg1000-ak230AI | 3/11/2026 | 6/17/2026 | A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor is… | |
| Analyzed | High (7.4) | 1.1% | — | H3C Magic B1 Firmware | 3/8/2026 | 6/17/2026 | A security vulnerability has been detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function Edit_BasicSSID_5G of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may… | |
| Analyzed | Critical (9.8) | 0.57% | — | H3C Mc102-g FirmwareH3C Magic Ba1500l Firmware | 1/6/2026 | 6/17/2026 | An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain… | |
| Deferred | Medium (6.9) | 0.37% | — | H3C SSL VPNAI | 12/30/2025 | 6/17/2026 | H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the login_submit.cgi endpoint and analyze response messages to distinguish between existing and non-existing accounts. | |
| Deferred | High (7.4) | 0.53% | — | H3C Magic B1AI | 12/7/2025 | 6/17/2026 | A weakness has been identified in H3C Magic B1 up to 100R004. The affected element is the function sub_44de0 of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be… |