Vulnerabilities

Summary — last 7 days

New vulnerabilities2,738▼ 488 vs. last week
Critical / high1,301▼ 189 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)229▼ 273 vs. last week
–

1,654 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.6)1.4%—Arista Cloudvision CUEAI10/6/202610/7/2026
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
Awaiting AnalysisHigh (7.1)0.29%—Juniper Cloudvision CUEAI10/6/202610/7/2026
Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.
Awaiting AnalysisMedium (6)0.25%—Arista Cloudvision CUEAI10/6/202610/7/2026
An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data.
Awaiting AnalysisCritical (9.3)0.28%—CloudvisionAI10/6/202610/7/2026
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their…
Awaiting AnalysisHigh (7.2)0.33%—Arista Cloudvision PortalAIArista Cloudvision SensorAI10/6/202610/7/2026
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
Awaiting AnalysisHigh (7.6)0.38%—Arista CloudvisionAI10/6/202610/7/2026
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
DeferredHigh (8.1)0.24%—Cozyvision SMS Alert Order NotificationsAI10/6/202610/6/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
Awaiting AnalysisMedium (6.9)0.10%—Samsung ManagedprovisioningAI10/2/202610/2/2026
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
DeferredHigh (7)0.09%—Anjvision Yssd-rtmp-h5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.
DeferredHigh (8.7)0.29%—Anjvision Yssd-rtmp-h5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation.
DeferredMedium (6.9)0.19%—Anjvision Yssd Rtmp H5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries.
DeferredHigh (7.2)0.34%—Anjvision Yssd Rtmp H5AI9/29/20269/29/2026
In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the…
DeferredMedium (5.3)0.21%—Anjvision Yssd Rtmp H5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access.
DeferredHigh (8.7)0.23%—Anjvision Yssd Rtmp H5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.
DeferredHigh (8.7)0.18%—Anjvision Yssd-rtmp-h5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as…
DeferredHigh (8.7)0.29%—Anjvision Yssd Rtmp H5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the…
DeferredCritical (9.3)0.33%—Anjvision Yssd-rtmp-h5AI9/29/20269/29/2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
DeferredHigh (8.8)0.24%💥 PoCIron Mountain Archiving Services EnvisionAI9/28/20269/28/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
AnalyzedHigh (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+3729/17/20269/22/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
DeferredHigh (7.8)0.20%—Geovision Gv-remote E-mapAI9/17/20269/18/2026
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully…
AnalyzedMedium (5.5)0.14%—Apple IpadosApple Iphone OSApple MacosApple Visionos9/14/20269/16/2026
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain.
AnalyzedMedium (5.5)0.16%—Apple IpadosApple Iphone OSApple MacosApple Tvos+29/14/20269/16/2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.
AnalyzedHigh (7.5)0.47%—Apple IpadosApple Iphone OSApple TvosApple Visionos+19/14/20269/16/2026
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
AnalyzedMedium (5.5)0.15%—Apple IpadosApple Iphone OSApple Visionos9/14/20269/16/2026
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able to access sensitive user data.
AnalyzedMedium (6.5)0.47%—Apple IpadosApple Iphone OSApple MacosApple Tvos+29/14/20269/16/2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected process…