CVE-2026-101155
- EPSS 0.56%
- Veröffentlicht 06.10.2026 19:38:23
- Zuletzt bearbeitet 07.10.2026 13:38:48
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Reposito...
CVE-2026-101154
- EPSS 0.56%
- Veröffentlicht 06.10.2026 19:38:22
- Zuletzt bearbeitet 07.10.2026 17:16:45
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.
- EPSS 0.33%
- Veröffentlicht 06.10.2026 19:38:07
- Zuletzt bearbeitet 07.10.2026 13:38:48
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
- EPSS 0.38%
- Veröffentlicht 06.10.2026 19:37:53
- Zuletzt bearbeitet 07.10.2026 13:38:48
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled...
CVE-2026-101151
- EPSS 0.31%
- Veröffentlicht 06.10.2026 19:37:53
- Zuletzt bearbeitet 07.10.2026 13:38:48
Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.
CVE-2026-101150
- EPSS 0.22%
- Veröffentlicht 06.10.2026 19:37:25
- Zuletzt bearbeitet 07.10.2026 13:38:48
Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
CVE-2026-101149
- EPSS 0.22%
- Veröffentlicht 06.10.2026 19:37:25
- Zuletzt bearbeitet 07.10.2026 13:38:48
Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
CVE-2026-101158
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:36:51
- Zuletzt bearbeitet 07.10.2026 13:38:48
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another Cloud...
- EPSS 99.91%
- Veröffentlicht 22.04.2026 08:15:10
- Zuletzt bearbeitet 08.09.2026 15:13:07
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-pl...
CVE-2024-12378
- EPSS 0.5%
- Veröffentlicht 08.05.2025 19:15:57
- Zuletzt bearbeitet 15.04.2026 00:35:42
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.