Vulnerabilities

Summary — last 7 days

New vulnerabilities2,716▼ 140 vs. last week
Critical / high1,239▼ 295 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 207 vs. last week
–

4,194 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.3)——TVU Networks Receiver TransceiverAI10/8/202610/9/2026
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints. Attackers can send unauthenticated GET…
DeferredCritical (9.3)——TVU Networks Receiver TransceiverAI10/8/202610/8/2026
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter.…
Awaiting AnalysisHigh (8.5)0.12%—Catonetworks SDP ClientAI9/30/20269/30/2026
Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.
Awaiting AnalysisLow (2.7)0.23%—HPE Networking Instant ONAI9/29/20269/30/2026
A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers…
Awaiting AnalysisLow (3)0.10%—HPE Networking Instant ONAI9/29/20269/30/2026
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Awaiting AnalysisLow (3.3)0.09%—HPE Networking Instant ONAI9/29/20269/30/2026
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Awaiting AnalysisMedium (4.1)0.09%—HPE Networking Instant ONAI9/29/20269/30/2026
A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported…
Awaiting AnalysisMedium (4.8)0.29%—HPE Networking Instant ONAI9/29/20269/30/2026
A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information…
Awaiting AnalysisMedium (4.9)0.31%—HPE Networking Instant ONAI9/29/20269/30/2026
A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes…
Awaiting AnalysisMedium (6.4)0.10%—HPE Networking Instant ONAI9/29/202610/1/2026
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
Awaiting AnalysisMedium (6.5)0.32%—HPE Networking Instant ONAI9/29/20269/30/2026
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected…
Awaiting AnalysisMedium (6.6)0.42%—HPE Networking Instant ON APSAI9/29/202610/1/2026
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the…
Awaiting AnalysisHigh (7.2)0.51%—HPE Networking Instant ON Access PointAI9/29/202610/6/2026
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating…
Awaiting AnalysisHigh (7.2)0.98%—HPE Networking Instant ONAI9/29/202610/1/2026
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying…
Awaiting AnalysisHigh (8.1)0.36%—HPE Networking Instant ONAI9/29/202610/1/2026
An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to…
Awaiting AnalysisCritical (9.6)0.31%—HPE Networking Instant ON APSAI9/29/202610/1/2026
Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Awaiting AnalysisCritical (9.8)0.54%—HPE Networking Instant ONAI9/29/202610/1/2026
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
Awaiting AnalysisCritical (9.8)0.56%—HPE Networking Instant ONAI9/29/20269/30/2026
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
Awaiting AnalysisHigh (8.2)0.20%—Networkupstools Network UPS ToolsAI9/28/20269/30/2026
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms…
DeferredMedium (5.9)0.19%—Nextscripts Social Networks Auto PosterAI9/27/20269/28/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,…
DeferredHigh (7.5)0.36%—Ciena Navigator Network Control SuiteAI9/25/20269/28/2026
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
DeferredHigh (7.8)0.19%—Networkmanager VpncAI9/25/20269/30/2026
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
DeferredHigh (7.8)0.19%—Networkmanager-vpncAI9/25/20269/30/2026
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN…
DeferredHigh (7.8)0.20%—Networkmanager FortisslvpnAI9/25/20269/30/2026
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject…
DeferredHigh (7.8)0.10%—Networkmanager SstpAI9/25/20269/30/2026
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then…