Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 36333 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3144 1 Ibm 1 Api Connect 2026-07-10 N/A 8.1 HIGH
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
CVE-2026-22927 2 Microsoft, Omnissa 2 Windows, Workspace One Tunnel 2026-07-10 N/A 7.8 HIGH
Omnissa Workspace ONEĀ® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CVE-2026-59207 1 N8n 1 N8n 2026-07-09 N/A 6.5 MEDIUM
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.
CVE-2011-4044 1 Arcinfo 3 Frontvue, Pcvue, Plantvue 2026-07-09 5.8 MEDIUM N/A
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods.
CVE-2011-4042 1 Arcinfo 3 Frontvue, Pcvue, Plantvue 2026-07-09 9.3 HIGH N/A
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.
CVE-2020-26869 1 Arcinfo 1 Pcvue 2026-07-09 5.0 MEDIUM 7.5 HIGH
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.
CVE-2026-48955 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.5 MEDIUM
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48956 1 Joomla 1 Joomla\! 2026-07-09 N/A 5.0 MEDIUM
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48957 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48958 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-12620 1 Microchip 2 Gridtime 3000, Gridtime 3000 Firmware 2026-07-09 N/A 6.5 MEDIUM
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
CVE-2026-48948 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2024-38909 1 Std42 1 Elfinder 2026-07-09 N/A 9.8 CRITICAL
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVE-2024-33844 1 Parrot 1 Anafi Firmware 2026-07-09 N/A 7.5 HIGH
The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong MAV_MISSION_TYPE.
CVE-2024-22899 1 Vinchin 1 Vinchin Backup And Recovery 2026-07-09 N/A 8.8 HIGH
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
CVE-2023-51926 1 Yonyou 1 Yonbip 2026-07-09 N/A 7.5 HIGH
YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.
CVE-2023-51906 1 Yonyou 1 Yonbip 2026-07-09 N/A 9.8 CRITICAL
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.
CVE-2023-51892 1 Weaver 1 E-cology 2026-07-09 N/A 9.8 CRITICAL
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.
CVE-2023-51142 1 Zkteco 1 Biotime 2026-07-09 N/A 7.5 HIGH
An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.
CVE-2023-50643 1 Evernote 1 Evernote 2026-07-09 N/A 9.8 CRITICAL
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.