Export limit exceeded: 370647 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370647 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370647 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-10577 | 1 Rockwellautomation | 1 1715 Ethernet/ip Communications Module | 2026-07-27 | N/A |
| A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. | ||||
| CVE-2026-53566 | 1 Citrix | 1 Secure Access Client | 2026-07-27 | N/A |
| Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20. | ||||
| CVE-2026-8590 | 1 Spotfire | 3 Spotfire Enterprise, Spotfire Enterprise With External Consumers, Spotfire On Kubernetes | 2026-07-27 | N/A |
| Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X. | ||||
| CVE-2026-15736 | 1 Snowflake | 1 Snowflake Sqlalchemy | 2026-07-27 | 8.3 High |
| Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic upsert endpoint, potentially enabling read access to data visible to the application's database role or modification of values within the same MERGE statement. Improper literal rendering of bound parameters when building certain Snowflake-specific table creation queries could allow SQL injection. An attacker may be able to exploit this by supplying a crafted string to any application endpoint that passes user-controlled data through the affected query-building API, potentially causing arbitrary data exfiltration within the scope of the connection role. Improper forwarding of connection configuration parameters could allow an attacker to cause the library to read arbitrary local files and transmit their contents to an attacker-controlled endpoint. An attacker may be able to exploit this in deployment environments that accept user-controlled connection parameters, potentially exposing sensitive files accessible to the application process. The fix is available in Snowflake SQLAlchemy version 1.11.0. Users must manually upgrade. | ||||
| CVE-2026-58475 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 6.1 Medium |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output encoding on rendered program names to execute arbitrary JavaScript in the browsers of any users viewing the affected page, with exploitation facilitated by the absence of a required passphrase or the default passphrase 'opendoor'. | ||||
| CVE-2026-58476 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 8.1 High |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the default configuration exposing these endpoints to unauthenticated users due to no required passphrase and a default credential of 'opendoor'. | ||||
| CVE-2026-60114 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 7.5 High |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory. | ||||
| CVE-2026-58477 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 8.2 High |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation. | ||||
| CVE-2026-58478 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 6.5 Medium |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase 'opendoor' to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible. | ||||
| CVE-2026-58479 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 9.8 Critical |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host. | ||||
| CVE-2025-12011 | 1 Rockwellautomation | 4 Compact Guardlogix 5370, Compactlogix 5370, Controllogix 5570 and 1 more | 2026-07-27 | N/A |
| A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). | ||||
| CVE-2025-12012 | 1 Rockwellautomation | 4 Compact Guardlogix 5370, Compactlogix 5370, Controllogix 5570 and 1 more | 2026-07-27 | N/A |
| A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). | ||||
| CVE-2025-11698 | 1 Rockwellautomation | 5 Compact Guardlogix 5380 Recovery Image, Compactlogix 5380 Recovery Image, Compactlogix 5480 Recovery Image and 2 more | 2026-07-27 | N/A |
| A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). | ||||
| CVE-2026-15392 | 1 Hmbrand | 1 Dbd::file | 2026-07-27 | 7.7 High |
| DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory. | ||||
| CVE-2026-60081 | 1 Hmbrand | 1 Dbi::profiledata | 2026-07-27 | 7.5 High |
| DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory. | ||||
| CVE-2026-15427 | 1 Tp-link | 1 Archer Vx1800v V1 | 2026-07-27 | N/A |
| An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device. | ||||
| CVE-2026-15428 | 1 Tp-link | 1 Archer Vx1800v V1 | 2026-07-27 | N/A |
| An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device. | ||||
| CVE-2026-15429 | 1 Tp-link | 1 Archer Vx1800v V1 | 2026-07-27 | N/A |
| A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges. | ||||
| CVE-2026-15747 | 1 Sri | 1 Mojolicious | 2026-07-27 | 9.1 Critical |
| Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation. | ||||
| CVE-2026-65435 | 2026-07-27 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | ||||