Export limit exceeded: 371926 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371926 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-44099 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 7.8 High |
| A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | ||||
| CVE-2026-44098 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 8.6 High |
| This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. | ||||
| CVE-2026-44097 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 7.1 High |
| A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service. | ||||
| CVE-2026-13584 | 2026-07-30 | N/A | ||
| Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. | ||||
| CVE-2026-44096 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 7.8 High |
| A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise. | ||||
| CVE-2026-44095 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 7.8 High |
| A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | ||||
| CVE-2026-44094 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 8.6 High |
| An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted. | ||||
| CVE-2026-44093 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 7.8 High |
| A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | ||||
| CVE-2026-44092 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 9.1 Critical |
| An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. | ||||
| CVE-2026-44091 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 9.1 Critical |
| An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. | ||||
| CVE-2026-44090 | 1 Phoenix Contact | 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more | 2026-07-30 | 9.8 Critical |
| Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. | ||||
| CVE-2026-65906 | 1 Jetbrains | 1 Teamcity | 2026-07-30 | 8.8 High |
| In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | ||||
| CVE-2026-65907 | 1 Jetbrains | 1 Teamcity | 2026-07-30 | 9.1 Critical |
| In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | ||||
| CVE-2026-17697 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-17725 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-17734 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-17737 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-17746 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-17754 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-17759 | 1 Google | 1 Chrome | 2026-07-30 | N/A |
| Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | ||||