7.3

CVSS4.0

CVE-2026-23717 - Out‑of‑Bounds Read in Simcenter Femap and Nastran Leading to Code Execution

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of t…

📅 Published: Feb. 10, 2026, 9:58 a.m. 🔄 Last Modified: April 17, 2026, 9 p.m.

7.3

CVSS4.0

CVE-2026-23716 - Out of Bounds Read in Siemens Simcenter Femap and Nastran Allowing Remote Code Execution

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of t…

📅 Published: Feb. 10, 2026, 9:58 a.m. 🔄 Last Modified: April 17, 2026, 9 p.m.

7.3

CVSS4.0

CVE-2026-23715 - Out-of-Bounds Write in Simcenter XDB File Parsing Leads to Code Execution

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds write vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of …

📅 Published: Feb. 10, 2026, 9:58 a.m. 🔄 Last Modified: April 18, 2026, 1 p.m.

7.3

CVSS4.0

CVE-2026-22923 - Local Arbitrary Code Execution via PDF Export in Siemens NX

A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected application contains a data validation vulnerability that could allow an attacker with local access to interfere with internal data during the PDF export process that could poten…

📅 Published: Feb. 10, 2026, 9:58 a.m. 🔄 Last Modified: April 16, 2026, 5:30 p.m.

6.2

CVSS4.0

CVE-2025-40587 -

A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2). The affected application allows arbitrary JavaScript code be included in document titles. This could allow an authenticated remote attacker to conduct a stored cross-site scripti…

📅 Published: Feb. 10, 2026, 9:58 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2024-52334 -

A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not encrypt the passwords properly. This could allow an attacker to recover the original passwords and might gain unauthorized access.

📅 Published: Feb. 10, 2026, 9:58 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2026-24343 - Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions

Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

📅 Published: Feb. 10, 2026, 9:28 a.m. 🔄 Last Modified: April 17, 2026, 9 p.m.

9.8

CVSS3.1

CVE-2026-23906 - Apache Druid: Authentication Bypass via LDAP Anonymous Bind

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind                           …

📅 Published: Feb. 10, 2026, 9:28 a.m. 🔄 Last Modified: April 18, 2026, 1 p.m.

5.4

CVSS3.1

CVE-2025-14895 - PopupKit <= 2.2.0 - Missing Authorization to Sensitive Information Disclosure and Data Deletion

The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not properly verifying that a user is authorized to access the /popup/logs REST API endpoint. This makes it possible for authenticated attackers, with Subsc…

📅 Published: Feb. 10, 2026, 9:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-1922 - The Events Calendar Shortcode & Block <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scr…

The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ecs-list-events` shortcode `message` attribute in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attrib…

📅 Published: Feb. 10, 2026, 9:26 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.
Total resulsts: 347398
Page 1543 of 34,740
« previous page » next page
Filters