VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

17220 CVEsRSS

CVE-2026-89792High· 7.1
2w ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before consuming variable-length fields

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list pa…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89786Critical· 9.1
2w ago

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-boun…

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-boun…

▾ MidnightLinux · LinuxEPSS 0.72%via NVD
CVE-2026-2380High· 7.4
2w ago

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded o…

▾ TwilightArista Networks · EOSEPSS 0.25%via NVD
CVE-2026-89774High· 8.8
2w ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. c…

▾ TwilightLinux · LinuxEPSS 0.40%via NVD
CVE-2026-89207Medium· 6.5
2w ago

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17)

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could al…

▾ SunlitSiemens · WTV676-HB6035 Web InterfaceEPSS 0.43%via NVD
CVE-2026-86341Medium· 4.4
2w ago

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have …

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have …

▾ Sunlitgitlab · gitlabEPSS 0.32%via NVD
CVE-2026-27565Critical· 9.8
2w ago

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

▾ MidnightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.97%via NVD
CVE-2026-27564High· 7.2
2w ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.7%via NVD
CVE-2026-27563High· 7.2
2w ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.7%via NVD
CVE-2026-27562High· 7.2
2w ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.7%via NVD
CVE-2026-27561High· 7.2
2w ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.7%via NVD
CVE-2026-27560High· 7.2
2w ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.7%via NVD
CVE-2026-27559High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27558High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges…

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges…

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27557High· 7.5
2w ago

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.71%via NVD
CVE-2026-27556High· 8.8
2w ago

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.89%via NVD
CVE-2026-27555High· 8.8
2w ago

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.89%via NVD
CVE-2026-27554High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27553Medium· 6.5
2w ago

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

▾ SunlitPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.56%via NVD
CVE-2026-27552High· 8.1
2w ago

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.60%via NVD
CVE-2026-27551High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27550High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27549High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27548High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27547High· 8.8
2w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27546Critical· 9.8
2w ago

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

▾ MidnightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 1.0%via NVD
CVE-2026-84408High· 8.8
2w ago

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.

▾ TwilightQualitySoft Corporation · QND PremiumEPSS 0.63%via NVD
CVE-2026-92355High· 8.7
2w ago

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

▾ TwilightOctopus Deploy · Octopus ServerEPSS 0.69%via NVD
CVE-2026-88263High· 7.5
2w ago

XikeStor Layer3 switches miss authentication for downloading configuration data

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or t…

▾ TwilightXikeStor · SKS8310-8XEPSS 0.58%via NVD
CVE-2026-92091Medium· 5.9PoC
2w ago

A flaw was found in jwcrypto

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacke…

▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.66%via NVD
CVEs tagged “cve.org” — page 233 · VulnSea