Export limit exceeded: 404419 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404419 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404419 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104629 | 1 Grid Protection Alliance | 2 Openhistorian, Openpdc | 2026-10-11 | 8.8 High |
| A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account. | ||||
| CVE-2026-105278 | 1 Grid Protection Alliance | 1 Openpdc | 2026-10-11 | 9.8 Critical |
| The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application. | ||||
| CVE-2026-104081 | 1 Kalcaddle | 1 Kodexplorer | 2026-10-11 | 8.1 High |
| KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload. | ||||
| CVE-2026-32645 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 6 Medium |
| Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts. | ||||
| CVE-2026-39460 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 8.1 High |
| Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication. | ||||
| CVE-2026-108107 | 1 Hotspotbilling | 1 Phpnuxbill | 2026-10-11 | 9.8 Critical |
| PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection. | ||||
| CVE-2026-108108 | 1 Hotspotbilling | 1 Phpnuxbill | 2026-10-11 | 7.1 High |
| PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan. | ||||
| CVE-2026-108109 | 1 Hotspotbilling | 1 Phpnuxbill | 2026-10-11 | 9.1 Critical |
| PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account. | ||||
| CVE-2026-28745 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 7.5 High |
| Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system. | ||||
| CVE-2026-33367 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 8.1 High |
| SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication. | ||||
| CVE-2026-29797 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 7.1 High |
| No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP. | ||||
| CVE-2026-39453 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 8.3 High |
| Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots. | ||||
| CVE-2026-33272 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 4.9 Medium |
| A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally. | ||||
| CVE-2026-15340 | 1 Savannah | 1 Lwip Smtp Client | 2026-10-11 | 9.8 Critical |
| lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow. | ||||
| CVE-2026-108110 | 1 Himovo | 1 Movo | 2026-10-11 | 6.8 Medium |
| MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints. | ||||
| CVE-2026-90983 | 1 Hayat Health Facilities | 1 Hayat Mobile | 2026-10-11 | 8.2 High |
| Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0. | ||||
| CVE-2016-20098 | 1 Toolbox-team | 1 Reddit-moderator-toolbox | 2026-10-11 | 5.4 Medium |
| Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions. | ||||
| CVE-2026-108158 | 1 Mynaparrot | 1 Plugnmeet-server | 2026-10-11 | 6.5 Medium |
| plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Attackers can supply ../ sequences so text or office documents are converted into page images, then fetch them unauthenticated through /download/uploadedFile/. | ||||
| CVE-2026-108159 | 1 Iflytek | 1 Astron-rpa | 2026-10-11 | 7.5 High |
| AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user. | ||||
| CVE-2026-108160 | 1 Iflytek | 1 Astron-rpa | 2026-10-11 | 7.5 High |
| AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user. | ||||