4.3

CVSS3.1

CVE-2025-15395 - IBM Jazz Foundation access control violation

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.

📅 Published: Feb. 2, 2026, 3:10 p.m. 🔄 Last Modified: Feb. 11, 2026, 8:34 p.m.

2

CVSS4.0

CVE-2026-1703 - Limited path traversal when installing wheel archives

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

📅 Published: Feb. 2, 2026, 2:43 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

9.8

CVSS3.1

CVE-2022-50981 - Multiple Innomic VibroLine VLX HD 5.0 and avibia AVLX weak password requirements

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

📅 Published: Feb. 2, 2026, 2:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2022-50980 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…

A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.

📅 Published: Feb. 2, 2026, 2:11 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2022-50979 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

📅 Published: Feb. 2, 2026, 2:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2022-50978 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

📅 Published: Feb. 2, 2026, 2:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2022-50977 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change vi…

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.

📅 Published: Feb. 2, 2026, 2:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2022-50976 - Innomic VibroLine Configurator and avibia Configurator allow unintended device reset via USB

A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.

📅 Published: Feb. 2, 2026, 2:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2022-50975 - Multiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated access to device configuration

An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.

📅 Published: Feb. 2, 2026, 2:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2026-1186 - Path Traversal in EAP Legislator

EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted by the victim upon o…

📅 Published: Feb. 2, 2026, 1:59 p.m. 🔄 Last Modified: April 18, 2026, 2:30 p.m.
Total resulsts: 347632
Page 1705 of 34,764
« previous page » next page
Filters