7.6

CVSS4.0

CVE-2026-2460 -

A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

πŸ“… Published: Feb. 24, 2026, 1:24 p.m. πŸ”„ Last Modified: Feb. 28, 2026, 2:23 a.m.

7.4

CVSS4.0

CVE-2026-2459 -

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

πŸ“… Published: Feb. 24, 2026, 1:21 p.m. πŸ”„ Last Modified: April 6, 2026, 1:55 p.m.

9.3

CVSS4.0

CVE-2025-14577 - PHP Function Injection in Slican NPC/IPL/IPM/IPU

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (S…

πŸ“… Published: Feb. 24, 2026, 1:21 p.m. πŸ”„ Last Modified: March 2, 2026, 2:10 p.m.

8.7

CVSS4.0

CVE-2026-1773 -

IEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame.Β Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of expl…

πŸ“… Published: Feb. 24, 2026, 1:13 p.m. πŸ”„ Last Modified: Feb. 28, 2026, 2:20 a.m.

5.3

CVSS4.0

CVE-2026-1772 -

RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

πŸ“… Published: Feb. 24, 2026, 1:03 p.m. πŸ”„ Last Modified: Feb. 28, 2026, 2:19 a.m.

5.3

CVSS4.0

CVE-2026-23969 - Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was reported where the default list for the…

πŸ“… Published: Feb. 24, 2026, 1:02 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:27 p.m.

5.3

CVSS4.0

CVE-2026-23980 - Apache Superset: Improper Neutralization of Special Elements used in a SQL Command

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. User…

πŸ“… Published: Feb. 24, 2026, 12:54 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 2:36 p.m.

7.1

CVSS4.0

CVE-2026-23982 - Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker with permissions to w…

πŸ“… Published: Feb. 24, 2026, 12:52 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 2:38 p.m.

2.3

CVSS4.0

CVE-2026-23983 - Apache Superset: Sensitive Data Exposure via REST API (disabled by default)

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the A…

πŸ“… Published: Feb. 24, 2026, 12:52 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 2:37 p.m.

7.1

CVSS4.0

CVE-2026-23984 - Apache Superset: SQLLab Read-Only Bypass on PostgreSQL

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data Manipulation Language (DML) statements …

πŸ“… Published: Feb. 24, 2026, 12:51 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:25 p.m.
Total resulsts: 344859
Page 1038 of 34,486
Β« previous page Β» next page
Filters