10

CVSS3.1

CVE-2026-27728 - OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in tracerou…

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell…

📅 Published: Feb. 25, 2026, 4:25 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

4.8

CVSS3.1

CVE-2026-20091 - Cisco UCS Manager and FXOS Software Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of…

📅 Published: Feb. 25, 2026, 4:24 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

4.4

CVSS3.1

CVE-2026-20037 - Cisco UCS Manager File Write Vulnerability

A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system.   This vulnerability exists because unnecessary privileges are given …

📅 Published: Feb. 25, 2026, 4:24 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

9.8

CVSS3.1

CVE-2026-27849 - Missing neutralization in Linksys MR9600, Linksys MX4200

Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

📅 Published: Feb. 25, 2026, 4:20 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

7.4

CVSS3.1

CVE-2026-20010 - Cisco Nexus 3000 and 9000 Series Switches Link Layer Discovery Protocol Denial of Service Vulnerabi…

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of speci…

📅 Published: Feb. 25, 2026, 4:18 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

6.5

CVSS3.1

CVE-2026-20036 - Cisco UCS Manager Software Command Injection Vulnerability

A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with valid administrative privileges to execute arbitrary commands on the underlying operating system of an affected device.    This vulnerability is…

📅 Published: Feb. 25, 2026, 4:14 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2026-20107 - Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability

A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attack…

📅 Published: Feb. 25, 2026, 4:14 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

7.4

CVSS3.1

CVE-2026-20051 - Cisco Nexus 3600-R and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerabili…

A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. This vulnerability is due to a logic error w…

📅 Published: Feb. 25, 2026, 4:14 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

5.4

CVSS3.1

CVE-2026-20122 - Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerab…

📅 Published: Feb. 25, 2026, 4:14 p.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

10

CVSS3.1

CVE-2026-20127 - Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.…

📅 Published: Feb. 25, 2026, 4:14 p.m. 🔄 Last Modified: April 22, 2026, 3:45 a.m.
Total resulsts: 347814
Page 1305 of 34,782
« previous page » next page
Filters