Vulnerabilities (CVE)

Total 398043 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-12852 1 Bouncycastle 1 Bc-java 2026-08-28 N/A 7.5 HIGH
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
CVE-2026-71368 2026-08-28 N/A 6.1 MEDIUM
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
CVE-2026-66404 2026-08-28 N/A 6.5 MEDIUM
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
CVE-2026-66406 2026-08-28 N/A 4.8 MEDIUM
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
CVE-2026-69665 2026-08-28 N/A 7.8 HIGH
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
CVE-2026-66403 2026-08-28 N/A 7.5 HIGH
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
CVE-2026-77989 2026-08-28 N/A N/A
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
CVE-2026-68959 2026-08-28 N/A 8.5 HIGH
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
CVE-2026-73542 2026-08-28 N/A 3.7 LOW
Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
CVE-2026-59769 2026-08-28 N/A 9.1 CRITICAL
FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.
CVE-2026-66407 2026-08-28 N/A 8.1 HIGH
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
CVE-2026-64940 2026-08-28 N/A 8.6 HIGH
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
CVE-2026-73335 2026-08-28 N/A 5.3 MEDIUM
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.
CVE-2026-66409 2026-08-28 N/A 5.3 MEDIUM
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.
CVE-2026-66405 2026-08-28 N/A 8.8 HIGH
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
CVE-2026-76137 2026-08-28 N/A 3.3 LOW
Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe.
CVE-2026-76148 2026-08-28 N/A 7.8 HIGH
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
CVE-2026-72506 2026-08-28 N/A 5.4 MEDIUM
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
CVE-2026-59561 2026-08-28 N/A 7.8 HIGH
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
CVE-2026-70408 2026-08-28 N/A 8.8 HIGH
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.