Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · sun

sun

· 5 Critical

Total CVEs

1,711

Critical

5

Products

200

Search All CVEs →

1,711

Products (200)

sunos609 CVEssolaris545 CVEsjre426 CVEsjdk395 CVEssdk127 CVEsopensolaris115 CVEsjava system web server32 CVEsjava system application server22 CVEsjava se21 CVEsjava system identity manager19 CVEsjava system directory server18 CVEsopenjdk17 CVEsjava system access manager16 CVEsray server software15 CVEsjava14 CVEsone application server13 CVEscobalt raq 3i12 CVEsjava system web proxy server12 CVEsone web server12 CVEscobalt raq 212 CVEsstaroffice10 CVEscluster8 CVEsj2se7 CVEssun fire7 CVEsjava desktop system7 CVEsjava system portal server6 CVEssolaris answerbook26 CVEsone directory server6 CVEsehrd6 CVEsvirtualbox5 CVEsiplanet messaging server5 CVEsjava web start5 CVEsopenoffice.org5 CVEscobalt raq 45 CVEssolstice adminsuite5 CVEsjava system communications express5 CVEsgrid engine4 CVEschilisoft4 CVEsiplanet directory server4 CVEsiplanet web server4 CVEsjava asp server4 CVEsjava plug-in4 CVEsjava system calendar server4 CVEsjava web console4 CVEsjavamail4 CVEsn1 grid engine4 CVEsnfs4 CVEsone messaging server4 CVEssolstice backup4 CVEsstoredge enterprise backup software3 CVEsone calendar server3 CVEsmanagement\+center3 CVEsmanagement center3 CVEscrypto accelerator 40003 CVEsjava system messaging server3 CVEscobalt raq3 CVEssecure global desktop3 CVEsj2ee3 CVEssparc enterprise server3 CVEsjsse3 CVEsjava enterprise system3 CVEsstoredge 6130 arrays3 CVEssolaris pc netlink2 CVEsjava system content delivery server2 CVEsxvm virtualbox2 CVEsfire x2200 m22 CVEssparc2 CVEsi-runbook2 CVEsnet connect software2 CVEssparc enterprise server t51402 CVEssparc enterprise server t51202 CVEssparc enterprise server t52202 CVEssparc enterprise server t52402 CVEsopensso enterprise2 CVEsopenwindows2 CVEsiplanet certificate management system2 CVEsnetra2 CVEsfire x2100 m22 CVEsjava system identity server2 CVEsnetra t5220 server2 CVEsvirtual desktop infrastructure2 CVEsembedded lights out manager2 CVEsj2me2 CVEsjava system web server plugin1 CVEsjava virtual machine1 CVEswbem services1 CVEsjava wireless toolkit for cldc1 CVEsweb-based enterprise management1 CVEsjavaserver web dev kit1 CVEscobalt raq xtr1 CVEsjmf1 CVEsjsf1 CVEslightweight availability collection tool1 CVEslinux1 CVEslogical domain manager1 CVEswireless toolkit1 CVEsn1 service provisioning system1 CVEsn1 system manager1 CVEsnetbeans developer1 CVEsnetdynamics1 CVEsnetra 12801 CVEsnetra cp3060 server1 CVEsnetra t2000 server1 CVEsnetra x4200m2 server1 CVEsnetra x4250 server1 CVEsnetra x44501 CVEswoodstock1 CVEsnss1 CVEsone administration server1 CVEschange manager1 CVEschainkey java code protection1 CVEsworkshop1 CVEsblade x84501 CVEsblade x84401 CVEsblade x84201 CVEsblade x84001 CVEspatch manager1 CVEspatchpro1 CVEsblade x6450 with server module software1 CVEsray windows connector1 CVEsrpc.ruserd1 CVEsrte1 CVEsscapp1 CVEsblade x6250 with server module software1 CVEsseam1 CVEsservice tag1 CVEssnmp management agent1 CVEsblade x6220 with server module software1 CVEsblade t6320 server module1 CVEssolaris gigabit ethernet driver1 CVEssolaris isp server1 CVEssolaris libfont1 CVEssolaris libxfont1 CVEsblade t6320 server1 CVEssolstice x.251 CVEssparc enterprise server t10001 CVEssparc enterprise server t20001 CVEssparc enterprise server t54401 CVEsblade t6300 server1 CVEsstarsuite1 CVEsstorage automated diagnostic environment1 CVEsstoragetek 35101 CVEsstoredge1 CVEsstoredge 3310 scsi array1 CVEsstoredge 3510 fc array1 CVEsstoredge qfs1 CVEsstoredge sam-qfs1 CVEsstoreedge performance suite1 CVEsstoreedge utilization suite1 CVEsblade 8000p modular system1 CVEssun fire server1 CVEssun ftp1 CVEssun pci ii driver1 CVEssunforum1 CVEssunone starter kit1 CVEsfire x4150 server1 CVEsfire x4200 server1 CVEsfire x4200m2 server1 CVEsfire x4240 server1 CVEsfire x4250 server1 CVEsfire x4440 server1 CVEsfire x4450 server1 CVEsfire x4500 server1 CVEsfire x4540 server1 CVEsfire x4600 server1 CVEsforte1 CVEsfire x4600m2 server1 CVEsblade 6000 modular system with chassis1 CVEshotjava browser1 CVEsintegrated lights-out manager1 CVEsblade 8000 modular system1 CVEsfire x4140 server1 CVEsiplanet messaging server messenger express1 CVEssunvts1 CVEsfire x4100m2 server1 CVEsfire x4100 server1 CVEsjava access manager1 CVEsjava active server1 CVEsjava active server pages1 CVEsultrasparc1 CVEsjava communications services delegated administrator1 CVEsfire x2250 server1 CVEsjava dynamic management kit1 CVEsjava embedding plugin1 CVEsjava platform micro edition1 CVEsjava runtime environment1 CVEsjava se development kit1 CVEsjava studio enterprise1 CVEsjava system access manager policy agent1 CVEsfire enterprise server t20001 CVEsblade 6048 modular system with chassis1 CVEsfire enterprise server t10001 CVEsjava system delegated administrator1 CVEsjava system directory proxy server1 CVEsextended system control facility xcp 10401 CVEsenterprise storage manager1 CVEsjava system ldap jdk1 CVEsjava system messenger express1 CVEsenterprise authentication mechanism1 CVEsdtmail1 CVEs

Recent Vulnerabilities

View all 1,711
CVE-2021-43360HIGH 8.8

Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and control the system or interrupt services.

CVE-2021-43359HIGH 8.8

Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.

CVE-2021-43358HIGH 7.5

Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.

CVE-2020-10510HIGH 8.1

Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

CVE-2020-10509MEDIUM 6.1

Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), attackers can inject arbitrary command into the system and launch XSS attack.

CVE-2020-10508HIGH 7.5

Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a specific URL and capture confidential information.

CVE-2016-1291

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

CVE-2016-1290

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.

CVE-2015-6313

Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv47565.

CVE-2016-1314

Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux80760.

CVE-2016-1350

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

CVE-2016-1349

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

CVE-2016-1348

Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.

CVE-2016-1344

The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.

CVE-2015-0718

Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.

CVE-2016-1329

Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.

CVE-2016-1331

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.

CVE-2016-1319

Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.

CVE-2016-1302

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.

CVE-2016-1310

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.

CVE-2016-1306

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466.

CVE-2015-6319

SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.

CVE-2015-0430

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality via vectors related to RPC Utility.

CVE-2015-0429

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to RPC Utility.

CVE-2015-0428

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Resource Control.