Fileserver 上传 API 中存在一个输入验证缺失的漏洞,允许拥有文件上传权限的经身份验证的攻击者执行存储型跨站脚本攻击(Stored XSS)。成功利用该漏洞可使攻击者劫持其他 CloudVision 用户的 Web 会话,从而可能获得对其账户及管理员权限的完全访问权。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | CloudVision Portal | 2026.2.0 |
affected |
2026.1.0≤ 2026.1.2 |
affected | ||
2025.3.0≤ 2025.3.3 |
affected | ||
1.0.0< 2025.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | CloudVision Portal | 2026.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102159 | 9.8 CRITICAL | Security Advisory 0190 |
| CVE-2026-101155 | 9.1 CRITICAL | Security Advisory 0189 |
| CVE-2026-102161 | 8.8 HIGH | Security Advisory 0190 |
| CVE-2026-102162 | 8.8 HIGH | Security Advisory 0193 |
| CVE-2026-102163 | 8.8 HIGH | Security Advisory 0195 |
| CVE-2026-101157 | 8.7 HIGH | Security Advisory 0192 |
| CVE-2026-102155 | 8.5 HIGH | Security Advisory 0190 |
| CVE-2026-101156 | 8.4 HIGH | Security Advisory 0192 |
| CVE-2026-101152 | 8.0 HIGH | Security Advisory 0187 |
| CVE-2026-101153 | 8.0 HIGH | Security Advisory 0188 |
| CVE-2026-102167 | 7.5 HIGH | Security Advisory 0197 |
| CVE-2026-102165 | 7.5 HIGH | Security Advisory 0198 |
| CVE-2026-101154 | 7.2 HIGH | Security Advisory 0189 |
| CVE-2026-102160 | 7.2 HIGH | Security Advisory 0190 |
| CVE-2026-102156 | 6.8 MEDIUM | Security Advisory 0191 |
| CVE-2026-102168 | 6.5 MEDIUM | Security Advisory 0194 |
| CVE-2026-102158 | 6.5 MEDIUM | Security Advisory 0190 |
| CVE-2026-102169 | 6.5 MEDIUM | Security Advisory 0194 |
| CVE-2026-102157 | 5.9 MEDIUM | Security Advisory 0190 |
| CVE-2026-101151 | 4.3 MEDIUM | Security Advisory 0187 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet