Search

Search Results (393701 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-27551 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more 2026-09-16 8.8 High
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
CVE-2026-27550 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more 2026-09-16 8.8 High
A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
CVE-2026-27549 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more 2026-09-16 8.8 High
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
CVE-2026-27548 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more 2026-09-16 8.8 High
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
CVE-2026-27546 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more 2026-09-16 9.8 Critical
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
CVE-2026-79551 2026-09-16 N/A
Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.
CVE-2026-39038 2026-09-16 N/A
BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.
CVE-2026-88261 2026-09-16 N/A
Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.
CVE-2026-80217 2026-09-16 N/A
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
CVE-2026-88616 1 Dromara 1 Ruoyi-vue-plus 2026-09-16 8.8 High
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components
CVE-2026-52484 2026-09-16 8.8 High
An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component
CVE-2026-79409 1 Webkul 1 Bagisto 2026-09-16 6.5 Medium
An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.
CVE-2026-79411 1 Webkul 1 Bagisto 2026-09-16 N/A
Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify that the actor is permitted to grant the requested role, does not prevent a user from changing their own role, and does not restrict assignment to roles whose permission set is a subset of the actor's own. By submitting a request that sets role_id to the Administrator role for their own account, a low-privileged administrator gains every admin-panel capability, including store configuration, payment gateway credentials, and customer PII.
CVE-2026-79425 1 Crmeb 1 Crmeb 2026-09-16 8.1 High
An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.
CVE-2026-88618 2026-09-16 6.5 Medium
1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.
CVE-2026-88619 1 1024-lab 1 Smartadmin 2026-09-16 8.1 High
1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a low-privileged authenticated user to access functionality intended for authorized administrators.
CVE-2026-88742 2026-09-16 N/A
Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.
CVE-2026-88743 2026-09-16 N/A
Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.
CVE-2026-88620 1 1024-lab 1 Smartadmin 2026-09-16 N/A
SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records belonging to other departments and users
CVE-2026-88621 2026-09-16 N/A
OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to unlink() when rejecting the upload, potentially causing file deletion and denial of service.