Total
398043 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-12852 | 1 Bouncycastle | 1 Bc-java | 2026-08-28 | N/A | 7.5 HIGH |
| In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check. | |||||
| CVE-2026-71368 | 2026-08-28 | N/A | 6.1 MEDIUM | ||
| F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed. | |||||
| CVE-2026-66404 | 2026-08-28 | N/A | 6.5 MEDIUM | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved. | |||||
| CVE-2026-66406 | 2026-08-28 | N/A | 4.8 MEDIUM | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege. | |||||
| CVE-2026-69665 | 2026-08-28 | N/A | 7.8 HIGH | ||
| SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |||||
| CVE-2026-66403 | 2026-08-28 | N/A | 7.5 HIGH | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved. | |||||
| CVE-2026-77989 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector. | |||||
| CVE-2026-68959 | 2026-08-28 | N/A | 8.5 HIGH | ||
| SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726. | |||||
| CVE-2026-73542 | 2026-08-28 | N/A | 3.7 LOW | ||
| Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information. | |||||
| CVE-2026-59769 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number. | |||||
| CVE-2026-66407 | 2026-08-28 | N/A | 8.1 HIGH | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered. | |||||
| CVE-2026-64940 | 2026-08-28 | N/A | 8.6 HIGH | ||
| Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console. | |||||
| CVE-2026-73335 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application. | |||||
| CVE-2026-66409 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot. | |||||
| CVE-2026-66405 | 2026-08-28 | N/A | 8.8 HIGH | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products. | |||||
| CVE-2026-76137 | 2026-08-28 | N/A | 3.3 LOW | ||
| Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe. | |||||
| CVE-2026-76148 | 2026-08-28 | N/A | 7.8 HIGH | ||
| CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product. | |||||
| CVE-2026-72506 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results. | |||||
| CVE-2026-59561 | 2026-08-28 | N/A | 7.8 HIGH | ||
| Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | |||||
| CVE-2026-70408 | 2026-08-28 | N/A | 8.8 HIGH | ||
| An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | |||||
