Common Vulnerabilities and Exposures (CVE)

CVE-2026-107103

Oct 7, 2026 18:07:23 UTC

This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted in...

CVE-2026-107104

Oct 7, 2026 18:06:51 UTC

This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the ...

CVE-2026-79809

Oct 7, 2026 18:06:41 UTC

An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assig...

CVE-2021-39301

Oct 7, 2026 18:06:39 UTC

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

CVE-2026-5703

Oct 7, 2026 18:06:27 UTC

Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user run...

CVE-2026-20038

Oct 7, 2026 18:05:53 UTC

A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an...

CVE-2026-76437

Oct 7, 2026 18:05:43 UTC

A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating s...

CVE-2026-76456

Oct 7, 2026 18:05:35 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mu...

CVE-2026-76498

Oct 7, 2026 18:05:21 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in ...

CVE-2021-21350

Oct 7, 2026 18:05:20 UTC

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No...

CVE-2026-76464

Oct 7, 2026 18:05:14 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address...

CVE-2026-76470

Oct 7, 2026 18:05:06 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address...

CVE-2026-95605

Oct 7, 2026 18:04:51 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Data Access: from n/a through 5.5.82.

CVE-2026-106067

Oct 7, 2026 18:04:41 UTC

A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the tru...

CVE-2021-39300

Oct 7, 2026 18:04:37 UTC

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.