5.9
CVE-2026-25605 - Unauthorized File Deletion Leading to Denial of Service in SICAM SIAPP SDK
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting inβ¦
8.6
CVE-2026-25573 - Command Injection via Caller-Provided Strings in Siemens SICAM SIAPP SDK
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.
5.9
CVE-2026-25572 - Unvalidated Length Input Causes Stack Overflow in Siemens SICAM SIAPP SDK
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the proceβ¦
5.9
CVE-2026-25571 - Stack Overflow via Oversized Input in SICAM SIAPP SDK
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the proceβ¦
7.5
CVE-2026-25570 -
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.
7.5
CVE-2026-25569 - Out-of-Bounds Write in Siemens SICAM SIAPP SDK Could Lead to Denial of Service or Arbitrary Code Exβ¦
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.
9.4
CVE-2025-40943 -
Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering an authorized user, who has the function right "Read diagnostics", to import a specially crafted trace file. The malicious trace file is insufficiently sanβ¦
2.4
CVE-2025-27769 -
A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging β¦
8.8
CVE-2026-3847 - Memory safety bugs fixed in Firefox 148.0.2
Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148.0.2.
6.5
CVE-2026-3846 - Same-origin policy bypass in the CSS Parsing and Computation component
Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.