Total
395674 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-82771 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |||||
| CVE-2026-82774 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82790 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |||||
| CVE-2026-82787 | 2026-09-16 | N/A | 9.8 CRITICAL | ||
| Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication. | |||||
| CVE-2026-82795 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-87727 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product. | |||||
| CVE-2026-82777 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82786 | 2026-09-16 | N/A | 6.3 MEDIUM | ||
| Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file. | |||||
| CVE-2026-68955 | 2026-09-16 | N/A | 7.8 HIGH | ||
| The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. | |||||
| CVE-2026-82762 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-82794 | 2026-09-16 | N/A | 8.8 HIGH | ||
| SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |||||
| CVE-2026-80217 | 2026-09-16 | N/A | 8.8 HIGH | ||
| Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands. | |||||
| CVE-2026-89156 | 1 Pcre | 1 Pcre2 | 2026-09-16 | N/A | 2.9 LOW |
| PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. | |||||
| CVE-2026-69646 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 8.3 HIGH |
| Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |||||
| CVE-2026-92126 | 2026-09-16 | N/A | N/A | ||
| Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on the classpath of the component that evaluates the script. | |||||
| CVE-2026-69642 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 6.5 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-89157 | 1 Pcre | 1 Pcre2 | 2026-09-16 | N/A | 5.7 MEDIUM |
| PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. | |||||
| CVE-2026-66308 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |||||
| CVE-2026-15412 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. | |||||
| CVE-2026-15634 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks. | |||||
