Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2026-16812 KEV
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…
Velocloud Orchestrator
5.2.3.14 / 6.1.3.4+
MEDIUM 6.0
CVE-2026-25620EPSS 10%
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Ne…
Ng Firewall
Mitigation only
MEDIUM 6.0
CVE-2026-25621
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure i…
Ng Firewall
Mitigation only
MEDIUM 6.0
CVE-2026-25622EPSS 10%
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On …
Ng Firewall
17.4.1+
MEDIUM 6.0
CVE-2026-25623EPSS 6%
An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generati…
Ng Firewall
17.4.1+
MEDIUM 5.8
CVE-2026-7473 KEV
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (G…
Eos
Mitigation only
CRITICAL 9.6
CVE-2025-2767
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…
Ng Firewall
Mitigation only
HIGH 8.8
CVE-2024-9188
Specially constructed queries cause cross platform scripting leaking administrator tokens
Ng Firewall
17.2+
HIGH 8.3
CVE-2024-9134
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL…
Ng Firewall
17.2+
CRITICAL 9.8
CVE-2024-9132
The administrator is able to configure an insecure captive portal script
Ng Firewall
after 17.1.1
HIGH 7.6
CVE-2024-47518
Specially constructed queries targeting ETM could discover active remote access sessions
Ng Firewall
after 17.1.1
HIGH 7.6
CVE-2024-47520
A user with advanced report application access rights can perform actions for which they are not authorized
Ng Firewall
after 17.1.1
HIGH 7.2
CVE-2024-9131
A user with administrator privileges can perform command injection
Ng Firewall
after 17.1.1
HIGH 7.1
CVE-2024-47519
Backup uploads to ETM subject to man-in-the-middle interception
Ng Firewall
after 17.1.1
MEDIUM 5.6
CVE-2024-9133
A user with administrator privileges is able to retrieve authentication tokens
Ng Firewall
after 17.1.1
MEDIUM 6.8
CVE-2024-47517
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
Ng Firewall
after 17.1.1
HIGH 7.8
CVE-2024-12831
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil…
Ng Firewall
Mitigation only
HIGH 7.3
CVE-2024-12830
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…
Ng Firewall
Mitigation only
MEDIUM 6.3
CVE-2024-12832
Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitr…
Ng Firewall
Mitigation only
HIGH 8.8
CVE-2024-12829
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…
Ng Firewall
Mitigation only
HIGH 8.8
CVE-2024-27889EPSS 9%
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user wi…
Ng Firewall
after 17.0
MEDIUM 6.5
CVE-2023-24547
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed…
Mos
after 0.39.4
HIGH 7.5
CVE-2023-3646
On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and …
Eos
4.29.2f+
MEDIUM 6.5
CVE-2023-24548
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware…
Eos
after 4.24.11m
HIGH 8.1
CVE-2023-24546
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor …
Cloudvision Portal
after 2021.3
HIGH 7.5
CVE-2023-24510
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
Eos
4.26.10m / 4.27.10m+
MEDIUM 6.5
CVE-2023-24512
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat…
Eos
4.26.10m / 4.27.9m+
HIGH 7.8
CVE-2023-24509
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with R…
Eos
4.24.11m / 4.25.10m+
HIGH 7.5
CVE-2023-24545
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by se…
Cloudeos
4.26.9m / 4.27.8m+
HIGH 7.5
CVE-2023-24511
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may resu…
Eos
4.26.10m / 4.27.9m+