Export limit exceeded: 393529 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (393529 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-27561 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 7.2 High |
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27560 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 7.2 High |
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27559 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27558 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27557 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 7.5 High |
| An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read. | ||||
| CVE-2026-27556 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device. | ||||
| CVE-2026-27555 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device. | ||||
| CVE-2026-27554 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27553 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 6.5 Medium |
| A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes. | ||||
| CVE-2026-27552 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.1 High |
| A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes. | ||||
| CVE-2026-27551 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27550 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27549 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27548 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27547 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 8.8 High |
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device. | ||||
| CVE-2026-27546 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 9.8 Critical |
| An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. | ||||
| CVE-2026-79551 | 2026-09-16 | N/A | ||
| Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. | ||||
| CVE-2026-92091 | 1 Redhat | 4 Ansible Automation Platform, Enterprise Linux, Openshift Ai and 1 more | 2026-09-16 | 5.9 Medium |
| A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacker can supply a JWK with a large key_ops array to an application that passes attacker-controlled key material to a public key-import API (reachable via ECDH-ES key agreement, OIDC dynamic client registration, DPoP, or ACME account key registration, among others) to consume excessive CPU time, resulting in a denial of service. | ||||
| CVE-2026-39038 | 2026-09-16 | N/A | ||
| BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx. | ||||
| CVE-2026-88261 | 2026-09-16 | N/A | ||
| Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1. | ||||