Export limit exceeded: 10074 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387163 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387163 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75163 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | 6.5 Medium |
| An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role. | ||||
| CVE-2026-75168 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | 6.3 Medium |
| An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/. | ||||
| CVE-2026-78745 | 1 Weyontv | 1 Hidptandroid | 2026-09-07 | N/A |
| An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd) | ||||
| CVE-2026-75164 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | 6.5 Medium |
| An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter. | ||||
| CVE-2026-75166 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution. | ||||
| CVE-2026-75167 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts. | ||||
| CVE-2026-75170 | 1 Hubcore | 1 Hubcore | 2026-09-07 | N/A |
| Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter. | ||||
| CVE-2026-75171 | 1 Hubcore | 1 Hubcore | 2026-09-07 | N/A |
| An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component. | ||||
| CVE-2022-26961 | 1 Italtel | 1 Netmatch-s | 2026-09-07 | N/A |
| Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it. | ||||
| CVE-2026-50894 | 1 Zhongshaofa | 1 Easyadmin | 2026-09-07 | N/A |
| easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload. | ||||
| CVE-2025-67066 | 1 Oasys | 1 Sysoa | 2026-09-07 | N/A |
| SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | ||||
| CVE-2026-71625 | 1 Slimkit | 1 Thinksns+ | 2026-09-07 | N/A |
| An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | ||||
| CVE-2026-82309 | 1 Perl | 1 Robots::validate | 2026-09-07 | N/A |
| Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client address, keeps the returned names matching the rule's domain, and issues a forward query for each until one resolves back to that address. Nothing bounds that list, and a client controls the reverse zone for its own address, so it chooses how many names the PTR answer holds. Net::DNS refetches a truncated answer over TCP by default, so the 512-byte UDP payload does not cap it either. Any client whose User-Agent matches a rule with a domain reaches _check_dns. Each forward name is distinct and client-chosen, so every query misses the local cache and is resolved against the authoritative servers for that domain. The queries are synchronous, so the caller is held until all of them answer or time out. | ||||
| CVE-2026-19057 | 1 Gastromenum | 1 Gastromenum Ticket And Qr Menu System | 2026-09-07 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31. | ||||
| CVE-2026-19081 | 1 Gastromenum | 1 Gastromenum Ticket And Qr Menu System | 2026-09-07 | 4.3 Medium |
| Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31. | ||||
| CVE-2026-19727 | 1 Yordam Information Technology Consulting, Training And Electronic Systems Industry And Trade Inc. | 1 Library Information And Document Automation Program | 2026-09-07 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library Information and Document Automation Program: before v22.2. | ||||
| CVE-2026-19205 | 1 Gastromenum | 1 Gastromenum Web Panel | 2026-09-07 | 7.5 High |
| Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. | ||||
| CVE-2026-85605 | 2 Andrii-kryvoviaz, Slinkapp | 2 Slink, Slink | 2026-09-07 | 5.3 Medium |
| Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks. | ||||
| CVE-2026-85608 | 1 Evil0ctal | 1 Douyin Tiktok Download Api | 2026-09-07 | 7.5 High |
| Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages. | ||||
| CVE-2026-85625 | 1 Crcn | 1 Sift.js | 2026-09-07 | 8.1 High |
| sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by default). As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript. Additionally, passing an untrusted query object containing a string $where directly to sift results in code execution under the default configuration. | ||||