Total
395674 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-82785 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | |||||
| CVE-2026-82779 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82766 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82772 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed. | |||||
| CVE-2026-82764 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed. | |||||
| CVE-2026-82769 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |||||
| CVE-2026-86701 | 2026-09-16 | N/A | 2.5 LOW | ||
| Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from the affected application. | |||||
| CVE-2026-82778 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | |||||
| CVE-2026-82796 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82782 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | |||||
| CVE-2026-85125 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites. | |||||
| CVE-2026-82763 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |||||
| CVE-2026-82793 | 2026-09-16 | N/A | 7.2 HIGH | ||
| Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product. | |||||
| CVE-2026-82765 | 2026-09-16 | N/A | 8.1 HIGH | ||
| Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP. | |||||
| CVE-2026-82788 | 2026-09-16 | N/A | 6.1 MEDIUM | ||
| Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |||||
| CVE-2026-82770 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed. | |||||
| CVE-2026-88263 | 2026-09-16 | N/A | 7.5 HIGH | ||
| XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host. | |||||
| CVE-2026-82780 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product. | |||||
| CVE-2026-82784 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output. | |||||
| CVE-2026-82768 | 2026-09-16 | N/A | 8.1 HIGH | ||
| Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP. | |||||
