9.8

CVSS3.1

CVE-2026-2248 - Unauthenticated Remote Root Shell Access via Web Console in METIS WIC

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compro…

πŸ“… Published: Feb. 11, 2026, 2:15 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

7.5

CVSS3.1

CVE-2026-2250 - Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests t…

πŸ“… Published: Feb. 11, 2026, 2:13 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

9.8

CVSS3.1

CVE-2025-12059 - Improper Access Control in Logo Software's Logo j-Platform

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logo j-Platform: from 3.29.6.4 before 3.34.8.9.

πŸ“… Published: Feb. 11, 2026, 1:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2026-1226 - Malicious TGML File Allows Untrusted Code Execution in EcoStruxure Building Operation

CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the application when maliciously crafted design content is processed through a TGML graphics file.

πŸ“… Published: Feb. 11, 2026, 1:49 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

7

CVSS4.0

CVE-2026-1227 - XML External Entity Disclosure in EBO TGML Upload

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Wor…

πŸ“… Published: Feb. 11, 2026, 1:45 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

9.4

CVSS3.1

CVE-2025-8668 - Reflected XSS in E-Kalite Software Hardware Engineering's Turboard

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS.This issue affects Turboard: from 2025.07 before 2026.02.Β  NOTE:…

πŸ“… Published: Feb. 11, 2026, 1:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-2337 - Refleccted XSS on Plunet BusinessManager

A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1.

πŸ“… Published: Feb. 11, 2026, 1:28 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2026-0910 - wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

πŸ“… Published: Feb. 11, 2026, 1:25 p.m. πŸ”„ Last Modified: April 15, 2026, 6:45 p.m.

1.7

CVSS4.0

CVE-2024-56807 - Media Streaming add-on

An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 202…

πŸ“… Published: Feb. 11, 2026, 12:20 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:29 p.m.

2

CVSS4.0

CVE-2024-56808 - Media Streaming add-on

A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versi…

πŸ“… Published: Feb. 11, 2026, 12:20 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:24 p.m.
Total resulsts: 349182
Page 1683 of 34,919
Β« previous page Β» next page
Filters