Total
398043 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66408 | 2026-08-28 | N/A | 4.6 MEDIUM | ||
| The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account. | |||||
| CVE-2026-67578 | 2026-08-28 | N/A | 7.5 HIGH | ||
| FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters. | |||||
| CVE-2026-68960 | 2026-08-28 | N/A | 8.5 HIGH | ||
| A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product installed and can receive UDP packets from that system. | |||||
| CVE-2026-77991 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution. | |||||
| CVE-2026-73537 | 2026-08-28 | N/A | 4.7 MEDIUM | ||
| Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered. | |||||
| CVE-2026-66411 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot. | |||||
| CVE-2026-66410 | 2026-08-28 | N/A | 4.8 MEDIUM | ||
| Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. | |||||
| CVE-2026-77035 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record. | |||||
| CVE-2026-66358 | 2026-08-28 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | |||||
| CVE-2026-68062 | 2026-08-28 | N/A | 8.5 HIGH | ||
| SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726. | |||||
| CVE-2026-77990 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. | |||||
| CVE-2026-67243 | 2026-08-28 | N/A | 7.2 HIGH | ||
| freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands. | |||||
| CVE-2026-66344 | 2026-08-28 | N/A | 6.7 MEDIUM | ||
| NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges. | |||||
| CVE-2026-77034 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event. | |||||
| CVE-2026-76149 | 2026-08-28 | N/A | 4.4 MEDIUM | ||
| CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file. | |||||
| CVE-2026-57279 | 2026-08-28 | N/A | 6.8 MEDIUM | ||
| Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product. | |||||
| CVE-2026-66839 | 2026-08-28 | N/A | 6.7 MEDIUM | ||
| NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges. | |||||
| CVE-2026-66109 | 2026-08-28 | N/A | 7.8 HIGH | ||
| A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |||||
| CVE-2026-65875 | 2026-08-28 | N/A | 7.1 HIGH | ||
| BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. | |||||
| CVE-2026-59504 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |||||
