Search

Search Results (399352 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-101022 1 Grid Protection Alliance 2 Openhistorian, Openpdc 2026-10-11 4.3 Medium
A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.
CVE-2026-104629 1 Grid Protection Alliance 2 Openhistorian, Openpdc 2026-10-11 8.8 High
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
CVE-2026-105278 1 Grid Protection Alliance 1 Openpdc 2026-10-11 9.8 Critical
The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.
CVE-2026-104081 1 Kalcaddle 1 Kodexplorer 2026-10-11 8.1 High
KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload.
CVE-2026-32645 1 Red Lion Controls 1 700 Series 2026-10-11 6 Medium
Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts.
CVE-2026-39460 1 Red Lion Controls 1 700 Series 2026-10-11 8.1 High
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.
CVE-2026-108107 1 Hotspotbilling 1 Phpnuxbill 2026-10-11 9.8 Critical
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.
CVE-2026-108108 1 Hotspotbilling 1 Phpnuxbill 2026-10-11 7.1 High
PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.
CVE-2026-108109 1 Hotspotbilling 1 Phpnuxbill 2026-10-11 9.1 Critical
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
CVE-2026-28745 1 Red Lion Controls 1 700 Series 2026-10-11 7.5 High
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
CVE-2026-33367 1 Red Lion Controls 1 700 Series 2026-10-11 8.1 High
SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.
CVE-2026-29797 1 Red Lion Controls 1 700 Series 2026-10-11 7.1 High
No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
CVE-2026-39453 1 Red Lion Controls 1 700 Series 2026-10-11 8.3 High
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
CVE-2026-33272 1 Red Lion Controls 1 700 Series 2026-10-11 4.9 Medium
A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
CVE-2026-15340 1 Savannah 1 Lwip Smtp Client 2026-10-11 9.8 Critical
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
CVE-2026-108110 1 Himovo 1 Movo 2026-10-11 6.8 Medium
MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.
CVE-2026-90983 1 Hayat Health Facilities 1 Hayat Mobile 2026-10-11 8.2 High
Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.
CVE-2016-20098 1 Toolbox-team 1 Reddit-moderator-toolbox 2026-10-11 5.4 Medium
Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions.
CVE-2026-108158 1 Mynaparrot 1 Plugnmeet-server 2026-10-11 6.5 Medium
plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Attackers can supply ../ sequences so text or office documents are converted into page images, then fetch them unauthenticated through /download/uploadedFile/.
CVE-2026-108159 1 Iflytek 1 Astron-rpa 2026-10-11 7.5 High
AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.