Export limit exceeded: 391636 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 391636 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 391636 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391636 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82578 | 1 Nextgen Healthcare | 1 Mirth Connect | 2026-09-13 | 7.5 High |
| When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks. | ||||
| CVE-2026-85979 | 1 Perforce Software | 1 Puppet Enterprise | 2026-09-13 | N/A |
| Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system. | ||||
| CVE-2026-38058 | 1 St Engineering Idirect | 3 3315-series Terminals, 9-series Terminals, Evolution Iq‑series Terminals | 2026-09-13 | 8.1 High |
| The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware. | ||||
| CVE-2026-38056 | 1 St Engineering Idirect | 3 3315-series Terminals, 9-series Terminals, Evolution Iq‑series Terminals | 2026-09-13 | 8.8 High |
| A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced. | ||||
| CVE-2026-85083 | 1 Carecam | 1 Anjia Ajl33pc0801 Firmware | 2026-09-13 | 6.8 Medium |
| The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise. | ||||
| CVE-2026-89009 | 1 Wavlink | 2 Wn535m1, Wn535m3 | 2026-09-13 | 9.1 Critical |
| WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise. | ||||
| CVE-2026-89010 | 1 Wavlink | 2 Wn535m1, Wn535m3 | 2026-09-13 | 9.8 Critical |
| WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string via sprintf() and passes it to system() without sanitization, enabling root-level command execution on the device. | ||||
| CVE-2026-81861 | 1 Schneider-electric | 4 Scadapack 312e, Scadapack 32, Scadapack 470 and 1 more | 2026-09-13 | N/A |
| CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality. | ||||
| CVE-2026-3869 | 1 Schneider-electric | 2 Modicon M580, Modicon M580 Safety | 2026-09-13 | N/A |
| CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC. | ||||
| CVE-2026-89260 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 7.5 High |
| MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter entities to read arbitrary local files or trigger outbound HTTP requests, with resolved entities reflected in error responses. | ||||
| CVE-2026-89261 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 6.5 Medium |
| MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results. | ||||
| CVE-2026-89262 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 7.5 High |
| MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints. | ||||
| CVE-2026-89263 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 5.3 Medium |
| MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply notifications without authorization. | ||||
| CVE-2026-89264 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 4.3 Medium |
| MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | ||||
| CVE-2026-89265 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 4.3 Medium |
| MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps. | ||||
| CVE-2026-54047 | 1 Lacisynchroni | 1 Server | 2026-09-13 | N/A |
| Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available. | ||||
| CVE-2026-7298 | 1 Ideasoft Software Industry And Trade Inc. | 1 Smart E-commerce | 2026-09-13 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-27378 | 2 Magepeopleteam, Wordpress | 2 Deposits And Partial Payments For Woocommerce, Wordpress | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | ||||
| CVE-2026-62102 | 1 Gato Graphql | 1 Gato Graphql | 2026-09-13 | 8.8 High |
| Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | ||||
| CVE-2026-62106 | 2 Cozy Vision Technologies Pvt. Ltd., Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-09-13 | 8.8 High |
| Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. | ||||
