Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-44099

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3000, CHARX SEC-3150, CHARX SEC-3050, CHARX SEC-3100
Provider severity
HIGH
Conflicts
2

CVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3000, CHARX SEC-3150, CHARX SEC-3050, CHARX SEC-3100
Provider severity
HIGH
Conflicts
2

CVE-2026-44097

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3000, CHARX SEC-3100, CHARX SEC-3150, CHARX SEC-3050
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-44096

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3000, CHARX SEC-3050, CHARX SEC-3100, CHARX SEC-3150
Provider severity
HIGH
Conflicts
2

CVE-2026-44095

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3000, CHARX SEC-3050
Provider severity
HIGH
Conflicts
2

CVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3100, CHARX SEC-3150, CHARX SEC-3000, CHARX SEC-3050
Provider severity
HIGH
Conflicts
2

CVE-2026-44093

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3050, CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3000
Provider severity
HIGH
Conflicts
2

CVE-2026-44092

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3150, CHARX SEC-3050, CHARX SEC-3000, CHARX SEC-3100
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-44091

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3150, CHARX SEC-3000, CHARX SEC-3100, CHARX SEC-3050
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-44090

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
CHARX SEC-3100, CHARX SEC-3150, CHARX SEC-3000, CHARX SEC-3050
Provider severity
CRITICAL
Conflicts
2

CVE-2026-4409

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any public post page, forge authorization keys and manage comment subscription preferences for arbitrary users

PUBLISHED
Vendor
wpkube
Product
Subscribe To Comments Reloaded
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44089

Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.

PUBLISHED
Vendor
Totolink
Product
EX1200L
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44088

SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Central Directory from the end). It can lead to remote code execution by allowing an attacker to combine a genuine, signed JAR file with a malicious ZIP file, causing the verification to pass but the malicious class to be loaded. This issue was fixed in version 1.2.1.

PUBLISHED
Vendor
Krajowa Izba Rozliczeniowa
Product
SzafirHost
Provider severity
HIGH
Conflicts
0

CVE-2026-44087

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources. This issue affects Apache APISIX: from 2.3 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44083

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuMagie
Provider severity
HIGH
Conflicts
0

CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "che

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4.21, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift Container Platform 4.20, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat OpenShift Container Platform 4.21, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat OpenShift Container Platform 4.20, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Container Platform 4.19
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44076

Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44075

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI session options.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44074

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44073

Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44072

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption under specific conditions.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44071

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would otherwise be caught and safely terminated by runtime protection.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44070

An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character conversion requests.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-4407

Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.

PUBLISHED
Vendor
Xpdf
Product
Xpdf
Provider severity
LOW
Conflicts
1

CVE-2026-44069

An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume translation input.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44068

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44067

A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to obtain limited information or cause a minor service disruption via crafted EA data.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44066

Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor service disruption.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44065

An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify limited data or cause a minor service disruption via crafted print data.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44064

An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44063

An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP entries via crafted filter input.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44062

A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44061

Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover authentication credentials via timing analysis.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44060

An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-4406

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using `echo` and `wp_die()`, which serves the response with a `Content-Type: text/html` header instead of `application/json`. The `wp_json_encode()` function does not HTML-encode angle b

PUBLISHED
Vendor
Gravity Forms
Product
Gravity Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44059

A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or cause a minor service disruption.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44058

An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44057

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
LOW
Conflicts
0

CVE-2026-44056

A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.2 allows a remote authenticated attacker to cause a denial of service, obtain limited information, or modify limited data.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44055

A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44054

Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote authenticated attacker to cause a denial of service by exploiting the reconnect mechanism.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44053

Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic attack.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44052

Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44051

An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink creation.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44050

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44049

An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44048

A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44047

An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.

PUBLISHED
Vendor
Netatalk
Product
Netatalk
Provider severity
HIGH
Conflicts
0

CVE-2026-44046

Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from 1.2.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
LOW
Conflicts
0

CVE-2026-44042

UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentication. In repeater/webgui/webutils.c:817, the wi_uudecode() function checks whether the input length exceeds the output buffer with a strict greater-than comparison (>), while the correct check should be greater-than-or-equal (>=). When strlen(authdata) equals sizeof(decode), the decoded output length (approximately 3/4 of input) does not overflow the buffer in current practice

PUBLISHED
Vendor
uvnc
Product
UltraVNC
Provider severity
LOW
Conflicts
0