VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15933 CVEsRSS

CVE-2026-73176High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-73175High· 7.1
1w ago

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust…

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.26%via NVD
CVE-2026-73174High· 8.7
1w ago

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive o…

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive o…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.16%via NVD
CVE-2026-73173High· 8.8
1w ago

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attack…

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attack…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.71%via NVD
CVE-2026-73172Critical· 9.3
1w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01…

▾ MidnightAdvantech · EKI-1242IEIMSEPSS 2.2%via NVD
CVE-2026-73171High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite …

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.52%via NVD
CVE-2026-73170High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated…

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.54%via NVD
CVE-2026-73169Medium· 6.3
1w ago

Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.…

Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.…

▾ SunlitAdvantech · EKI-1242IEIMSEPSS 0.54%via NVD
CVE-2026-73167High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-73166High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.70%via NVD
CVE-2026-73165High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-92359Low· 3.1
1w ago

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipu…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.27%via NVD
CVE-2026-19535High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to …

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.24%via NVD
CVE-2026-88817High· 8.7
1w ago

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, …

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, …

▾ TwilightCuriosity GmbH · Curiosity WorkspaceEPSS 0.35%via NVD
CVE-2026-92360Medium· 6.3
1w ago

A weakness has been identified in ag-ui-protocol ag-ui 1.0

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_STA…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.21%via NVD
CVE-2026-73163High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-73164High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-92455Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /a…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.36%via NVD
CVE-2026-92458Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/produc…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.35%via NVD
CVE-2026-92457Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/i…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-92456High· 7.1PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

▾ Midnightguchengwuyue · yshop-crmEPSS 0.50%via NVD
CVE-2026-92463Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.46%via NVD
CVE-2026-92460Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.45%via NVD
CVE-2026-92461Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.38%via NVD
CVE-2026-92459Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can in…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-40854High· 8.7
1w ago

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding fil…

▾ TwilightWNC · T-Mobile 5G Box IDUvia NVD
CVE-2026-92462Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /adm…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-58146Critical· 9.4
1w ago

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is d…

▾ MidnightWNC · T-Mobile 5G Box IDUvia NVD
CVE-2026-40855Critical· 9.3
1w ago

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameter…

▾ MidnightWNC · T-Mobile 5G Box IDUvia NVD
CVE-2026-92465High· 7.6
1w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

▾ TwilightThemeum · wp-megamenuEPSS 0.38%via NVD
CVEs tagged “cve.org” — page 181 · VulnSea