4.3
CVE-2025-15395 - IBM Jazz Foundation access control violation
IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.
2
CVE-2026-1703 - Limited path traversal when installing wheel archives
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.
9.8
CVE-2022-50981 - Multiple Innomic VibroLine VLX HD 5.0 and avibia AVLX weak password requirements
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.
6.5
CVE-2022-50980 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…
A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.
6.5
CVE-2022-50979 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…
An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).
7.5
CVE-2022-50978 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).
7.5
CVE-2022-50977 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.
7.7
CVE-2022-50976 - Innomic VibroLine Configurator and avibia Configurator allow unintended device reset via USB
A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.
8.8
CVE-2022-50975 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated access to device configuration
An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.
8.6
CVE-2026-1186 - Path Traversal in EAP Legislator
EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted by the victim upon o…