| | CVE-2026-20212 | Cisco | critical | 9.8 | 0.5%
| | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an u… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-78689 | F5 | high | 8.1 | 0.4%
| | Description
NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list p… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-78222 | F5 | high | 7.5 | — | | A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() c… | Sep 2, 2026 | Sep 2, 2026 |
| | CVE-2026-77180 | F5 | high | 8.3 | 0.3%
| | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exi… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-66842 | F5 | high | 8.8 | 0.2%
| | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrat… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-66362 | F5 | high | 8.1 | 0.3%
| | Description:
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection … | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-19475 | Grafana | medium | 6.5 | 0.4%
| | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-333… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-14199 | Grafana | high | 7.1 | 0.3%
| | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syn… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-12704 | Grafana | medium | 6.8 | 0.3%
| | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-32773 | Apache | medium | 6.1 | 0.3%
| | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious … | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-84375 | Red Hat | high | 7.5 | — | | A flaw was found in js-yaml, a JavaScript YAML parser. An attacker can exploit this by providing a s… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84641 | Red Hat | high | 8.3 | — | | A flaw was found in Thunderbird. A remote attacker, by operating a malicious Internet Message Access… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84373 | Red Hat | medium | 5.9 | — | | A flaw was found in Vitest, a testing framework. A remote attacker, able to reach an exposed develop… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84637 | Red Hat | high | 8.8 | — | | A flaw was found in Thunderbird. Malicious calendar invitations could use file URI attachments to la… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-73783 | HPE | medium | 4.9 | 0.3%
| | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could all… | Sep 1, 2026 | Sep 2, 2026 |
| | CVE-2026-73782 | HPE | high | 8.8 | 0.3%
| | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unau… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73781 | HPE | high | 8.4 | 0.3%
| | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote … | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73780 | HPE | high | 8.3 | 0.2%
| | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a … | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73779 | HPE | high | 8.2 | 0.2%
| | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potential… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73778 | HPE | high | 8.1 | 0.3%
| | A vulnerability exists in the Credential Manager component that may allow for unauthorized administr… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73777 | HPE | high | 8.1 | 0.3%
| | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially a… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73776 | HPE | high | 7.9 | 0.1%
| | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Succes… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73774 | HPE | high | 7.6 | 0.2%
| | A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead … | Sep 1, 2026 | Sep 2, 2026 |
| | CVE-2026-73772 | HPE | medium | 6.5 | 0.2%
| | Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unaut… | Sep 1, 2026 | Sep 2, 2026 |
| | CVE-2026-73771 | HPE | high | 7.5 | 0.3%
| | An authentication vulnerability exists in the AOS-CX management interface and API that may allow imp… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73770 | HPE | high | 7.3 | 0.1%
| | An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could … | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73768 | HPE | high | 7.3 | 0.1%
| | A vulnerability exists in the command line interface of AOS-CX that may allow for improper processin… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73767 | HPE | high | 7.2 | 0.9%
| | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Succe… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73766 | HPE | high | 7.2 | 1.0%
| | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote … | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73765 | HPE | high | 7.2 | 0.6%
| | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitati… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73763 | HPE | high | 7.1 | 0.3%
| | A vulnerability exists in a management component that could allow an unauthenticated adjacent attack… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73758 | HPE | medium | 6.5 | 0.3%
| | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation c… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73755 | HPE | medium | 5.7 | 0.3%
| | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation c… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73753 | HPE | high | 8.8 | 0.3%
| | Exploitation through affected command-line operations could allow an authenticated low-privileged us… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73752 | HPE | high | 8.8 | 0.3%
| | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successfu… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73751 | HPE | high | 8.8 | 0.3%
| | An authenticated user with low-privileged access could submit crafted input through the web-based ma… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73750 | HPE | high | 8.8 | 0.5%
| | Vulnerabilities exist in the authentication module that may improperly process malformed or truncate… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-73749 | HPE | critical | 9.8 | 0.5%
| | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malfo… | Sep 1, 2026 | Sep 3, 2026 |
| | CVE-2026-84311 | Red Hat | medium | 5.5 | — | | A flaw was found in pypdf, a pure-python PDF library. A remote attacker can exploit this vulnerabili… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84310 | Red Hat | medium | 5.5 | — | | A flaw was found in pypdf. A remote attacker could craft a malicious PDF document with specially des… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84202 | Red Hat | high | 8.8 | — | | A flaw was found in ModelScope. This vulnerability arises from the use of PyYAML's unsafe yaml.Loade… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83618 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript XML parser and serializer module. A remote attacker could b… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83616 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript module for parsing and serializing XML. An attacker can exp… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83615 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript library for parsing XML documents. A remote attacker could … | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83614 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom. Two independent quadratic paths in the XML DOM (Document Object Model) p… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83613 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript module for parsing XML (Extensible Markup Language) documen… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83612 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript module used for parsing HTML documents. This vulnerability … | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83611 | Red Hat | medium | 5.3 | — | | A flaw was found in xmldom, a JavaScript XML DOM parser. The DOMParser.parseFromString() function ca… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83610 | Red Hat | medium | 5.3 | — | | A flaw was found in xmldom, a JavaScript module for parsing and serializing XML. The Document.create… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83608 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript module for parsing and serializing XML. A remote attacker c… | Sep 1, 2026 | Sep 1, 2026 |