Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25809

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.

PUBLISHED
Vendor
Praskla-Technology
Product
assessment-placipy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25808

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.

PUBLISHED
Vendor
fedify-dev
Product
hollo
Provider severity
HIGH
Conflicts
0

CVE-2026-25807

ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any remote attacker can connect to this port using a simple socket script. An attacker who connects to a ZAI-Shell P2P session running in --no-ai mode can send arbitrary system commands. If the host user approves the command without reviewing its contents, the com

PUBLISHED
Vendor
TaklaXBR
Product
zai-shell
Provider severity
HIGH
Conflicts
0

CVE-2026-25806

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:email/status, and DELETE /api/students/:email routes in backend/src/routes/student.routes.ts only enforce authentication using authenticateToken but do not enforce authorization. The application does not verify whether the authenticated user owns the student record being accessed, has an administrative / staff role, or is permitted to modify or delete

PUBLISHED
Vendor
Praskla-Technology
Product
assessment-placipy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25805

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values could be used without the user having a chance to notice it. Patched in Zed Editor 0.219.4 which includes expandable tool call details.

PUBLISHED
Vendor
zed-industries
Product
zed
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25804

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.

PUBLISHED
Vendor
antrea-io
Product
antrea
Provider severity
HIGH
Conflicts
1

CVE-2026-25803

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.

PUBLISHED
Vendor
denpiligrim
Product
3dp-manager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25802

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version 0.10.8-alpha.9 fixes the issue.

PUBLISHED
Vendor
QuantumNous
Product
new-api
Provider severity
HIGH
Conflicts
0

CVE-2026-25800

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particul

PUBLISHED
Vendor
quinn-rs
Product
quinn
Provider severity
HIGH
Conflicts
0

CVE-2026-2580

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive

PUBLISHED
Vendor
flippercode
Product
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
Provider severity
HIGH
Conflicts
0

CVE-2026-25799

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25798

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25797

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails to sanitize the input before writing it into the PostScript header. An attacker can provide a malicous file and inject arbitrary PostScript code. When the resulting file is processed by a printer or a viewer (like Ghostscript), the injected code is interpreted and executed. The html encoder does no

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25796

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25795

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointer dereference and crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25794

A flaw was found in ImageMagick. When processing images with large dimensions, the `WriteUHDRImage` function in `coders/uhdr.c` uses integer arithmetic that can overflow. This overflow leads to an undersized memory allocation, followed by an out-of-bounds write. A remote attacker could exploit this vulnerability by providing a specially crafted image, potentially causing a denial of service or, in some cases, arbitrary code execution.

PUBLISHED
Vendor
ImageMagick, Red Hat, Red Hat
Product
ImageMagick, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
Provider severity
HIGH
Conflicts
2

CVE-2026-25793

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

PUBLISHED
Vendor
slackhq
Product
nebula
Provider severity
HIGH
Conflicts
0

CVE-2026-25792

Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path / binary hijacking vulnerability that allows a local attacker to execute arbitrary code when the affected Windows application launches explorer.exe without using an absolute path. The vulnerable behavior is triggered when the user double-clicks the application’s tray icon, which opens the directory containing the most recent screenshot captured by the application. By placing a

PUBLISHED
Vendor
greenshot
Product
greenshot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25791

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored without a cleanup/expiry path in this flow, an unauthenticated remote actor can repeatedly create sessions and drive memory exhaustion. This vulnerability is fixed in 1.7.0.

PUBLISHED
Vendor
BishopFox
Product
sliver
Provider severity
HIGH
Conflicts
1

CVE-2026-25790

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, multiple stack-based buffer overflows exist in the Security Configuration Assessment (SCA) decoder (`wazuh-analysisd`). The use of `sprintf` with a floating-point (`%lf`) format specifier on a fixed-size 128-byte buffer allows a remote attacker to overflow the stack. A specially crafted JSON event can trigger this overflow, leading to a denial of se

PUBLISHED
Vendor
wazuh
Product
wazuh
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2579

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
wpxpo
Product
WowStore – Store Builder & Product Blocks for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-25789

Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file to be uploaded. This would result in malitcious JavaScript execution in the context of the authenticated user's session without requiring the file to be uploaded, potentially leading to session hijacking or credential theft.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC S7-1500 CPU 1513F-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 CPU 1517-3 PN, SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC S7-1500 CPU 1511C-1 PN, SIPLUS S7-1500 CPU 1513F-1 PN, SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL, SIMATIC S7-1500 Software Controller CPU 1508S V2, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 Software Controller CPU 1508S F V4, SIMATIC ET 200SP CPU 1514SPT F-2 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1511F-1 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL, SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL, SIPLUS ET 200SP CPU 1510SP-1 PN RAIL, SIMATIC ET 200SP CPU 1514SP-2 PN, SIMATIC S7-1500 CPU 1518-3 PN, SIMATIC S7-1500 CPU 1518T-3 PN, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIPLUS S7-1500 CPU 1515F-2 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S F V2, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1516pro-2 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL, SIMATIC S7-1500 CPU 1518-4 PN/DP, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1511T-1 PN, SIMATIC S7-1500 Software Controller Linux V2, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1517F-3 PN/DP, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL, SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs, SIPLUS S7-1500 CPU 1511-1 PN TX RAIL, SIMATIC S7-1500 CPU 1513pro-2 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIPLUS ET 200SP CPU 1510SP-1 PN, SIMATIC ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 CPU 1515T-2 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1517T-3 PN, SIMATIC ET 200SP CPU 1514SPT-2 PN, SIMATIC S7-1500 Software Controller CPU 1507S V2, SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN, SIPLUS ET 200SP CPU 1510SP-1 PN RAIL, SIMATIC S7-1500 CPU 1513F-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL, SIMATIC S7-1500 CPU 1511TF-1 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S TF V3, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN RAIL, SIMATIC S7-1500 CPU 1517F-3 PN/DP, SIMATIC S7-1500 Software Controller CPU 1507S F V3, SIPLUS ET 200SP CPU 1512SP-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN RAIL, SIMATIC S7-1500 Software Controller CPU 1508S V3, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 CPU 1516T-3 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518TF-3 PN, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S F V4, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIPLUS S7-1500 CPU 1515F-2 PN RAIL, SIPLUS S7-1500 CPU 1518-4 PN/DP, SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-PLCSIM Advanced, SIMATIC S7-1500 CPU 1517TF-3 PN, SIMATIC S7-1500 CPU 1517-3 PN/DP, SIMATIC S7-1500 CPU 1517T-3 PN/DP, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 CPU 1513pro F-2 PN, SIMATIC S7-1500 CPU 1511F-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1516T-3 PN/DP, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1511TF-1 PN, SIMATIC ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 CPU 1517TF-3 PN/DP, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC S7-1500 CPU 1518F-3 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL, SIMATIC Drive Controller CPU 1504D TF, SIMATIC ET 200SP CPU 1512SP-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1515T-2 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1511-1 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIPLUS S7-1500 CPU 1515F-2 PN, SIMATIC ET 200SP CPU 1514SP F-2 PN, SIMATIC S7-1500 Software Controller CPU 1508S F V2, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1518F-4 PN/DP, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs, SIMATIC S7-1500 CPU 1516pro F-2 PN, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC Drive Controller CPU 1507D TF, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1517F-3 PN, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIPLUS S7-1500 CPU 1511-1 PN TX RAIL, SIMATIC S7-1500 CPU 1511T-1 PN, SIMATIC S7-1500 CPU 1515TF-2 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN, SIMATIC ET 200SP CPU 1510SP-1 PN, SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S V4, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1515F-2 PN, SIPLUS ET 200SP CPU 1510SP-1 PN, SIPLUS S7-1500 CPU 1513F-1 PN, SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 Software Controller CPU 1508S F V3, SIMATIC S7-1500 CPU 1516TF-3 PN/DP, SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN, SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK, SIMATIC S7-1500 CPU 1518TF-4 PN/DP, SIMATIC S7-1500 Software Controller Linux V3, SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC S7-1500 CPU 1516TF-3 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S V3, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S V4, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC S7-1500 CPU 1515TF-2 PN, SIMATIC S7-1500 CPU 1518T-4 PN/DP, SIPLUS ET 200SP CPU 1510SP F-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S T V3
Provider severity
HIGH
Conflicts
2

CVE-2026-25787

Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 Software Controller CPU 1507S V2, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIPLUS S7-1500 CPU 1518-4 PN/DP, SIMATIC S7-1500 Software Controller CPU 1508S TF V3, SIMATIC S7-1500 CPU 1518T-4 PN/DP, SIPLUS S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1513F-1 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1517TF-3 PN/DP, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 CPU 1511TF-1 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1511T-1 PN, SIMATIC S7-1500 CPU 1515T-2 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC S7-PLCSIM Advanced, SIMATIC S7-1500 CPU 1518-4 PN/DP, SIMATIC S7-1500 CPU 1511TF-1 PN, SIPLUS ET 200SP CPU 1510SP-1 PN, SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL, SIMATIC ET 200SP CPU 1510SP-1 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S F V2, SIMATIC S7-1500 CPU 1517-3 PN/DP, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC ET 200SP CPU 1514SPT F-2 PN, SIMATIC S7-1500 Software Controller CPU 1507S F V3, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518T-3 PN, SIMATIC Drive Controller CPU 1504D TF, SIPLUS S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC ET 200SP CPU 1514SP-2 PN, SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL, SIMATIC S7-1500 CPU 1518F-3 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC Drive Controller CPU 1507D TF, SIMATIC S7-1500 CPU 1518TF-3 PN, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs, SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIMATIC ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S V4, SIMATIC S7-1500 Software Controller CPU 1508S F V2, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1515F-2 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN, SIPLUS S7-1500 CPU 1515F-2 PN RAIL, SIMATIC S7-1500 CPU 1517F-3 PN/DP, SIMATIC S7-1500 Software Controller CPU 1507S F V4, SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC S7-1500 CPU 1518TF-4 PN/DP, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN, SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN, SIPLUS ET 200SP CPU 1510SP F-1 PN, SIMATIC S7-1500 CPU 1516pro-2 PN, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs, SIMATIC S7-1500 CPU 1516T-3 PN/DP, SIMATIC S7-1500 CPU 1513-1 PN, SIPLUS ET 200SP CPU 1510SP-1 PN RAIL, SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1517F-3 PN, SIMATIC S7-1500 CPU 1517TF-3 PN, SIMATIC S7-1500 CPU 1516TF-3 PN/DP, SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL, SIMATIC S7-1500 CPU 1516TF-3 PN, SIPLUS S7-1500 CPU 1511-1 PN TX RAIL, SIMATIC S7-1500 CPU 1513pro-2 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 Software Controller CPU 1508S T V3, SIPLUS S7-1500 CPU 1515F-2 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC S7-1500 CPU 1517-3 PN, SIMATIC S7-1500 Software Controller CPU 1507S V3, SIMATIC ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 Software Controller Linux V3, SIMATIC S7-1500 CPU 1513pro F-2 PN, SIMATIC S7-1500 CPU 1515T-2 PN, SIMATIC S7-1500 Software Controller CPU 1507S V4, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIMATIC ET 200SP CPU 1512SP-1 PN, SIPLUS S7-1500 CPU 1515F-2 PN, SIPLUS S7-1500 CPU 1518F-4 PN/DP, SIMATIC S7-1500 Software Controller CPU 1508S V2, SIMATIC S7-1500 CPU 1517F-3 PN/DP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS S7-1500 CPU 1511-1 PN TX RAIL, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK, SIPLUS S7-1500 CPU 1513F-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 CPU 1511T-1 PN, SIMATIC ET 200SP CPU 1514SPT-2 PN, SIMATIC S7-1500 Software Controller Linux V2, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1516T-3 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1516pro F-2 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN RAIL, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1512C-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS ET 200SP CPU 1512SP-1 PN RAIL, SIMATIC ET 200SP CPU 1514SP F-2 PN, SIPLUS ET 200SP CPU 1510SP-1 PN RAIL, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S V3, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP, SIMATIC S7-1500 CPU 1518-3 PN, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 CPU 1515TF-2 PN, SIMATIC S7-1500 CPU 1515TF-2 PN, SIPLUS ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S F V3, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL, SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL, SIMATIC S7-1500 CPU 1517T-3 PN, SIMATIC S7-1500 Software Controller CPU 1508S F V4, SIMATIC S7-1500 CPU 1517T-3 PN/DP, SIMATIC S7-1500 CPU 1513F-1 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC ET 200SP CPU 1510SP-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN
Provider severity
CRITICAL
Conflicts
2

CVE-2026-25786

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN, SIMATIC S7-1500 Software Controller CPU 1508S V4, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S V2, SIPLUS S7-1500 CPU 1518-4 PN/DP, SIMATIC S7-1500 Software Controller CPU 1508S F V3, SIMATIC S7-1500 Software Controller CPU 1508S T V3, SIMATIC ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 CPU 1511TF-1 PN, SIPLUS S7-1500 CPU 1511-1 PN TX RAIL, SIMATIC S7-1500 Software Controller CPU 1507S F V2, SIMATIC S7-1500 CPU 1517F-3 PN/DP, SIMATIC S7-1500 CPU 1511T-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1515TF-2 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1513-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC S7-1500 CPU 1517T-3 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1517TF-3 PN, SIPLUS ET 200SP CPU 1512SP-1 PN, SIMATIC ET 200SP CPU 1512SP-1 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1511TF-1 PN, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC ET 200SP CPU 1514SP F-2 PN, SIPLUS S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1517T-3 PN/DP, SIPLUS S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 CPU 1517TF-3 PN/DP, SIMATIC S7-1500 Software Controller CPU 1508S F V4, SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 Software Controller Linux V2, SIMATIC S7-1500 Software Controller CPU 1507S V4, SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK, SIPLUS ET 200SP CPU 1510SP-1 PN, SIPLUS S7-1500 CPU 1511F-1 PN, SIPLUS ET 200SP CPU 1510SP-1 PN RAIL, SIMATIC S7-1500 CPU 1516T-3 PN/DP, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC ET 200SP CPU 1514SPT F-2 PN, SIPLUS S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1515T-2 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIPLUS ET 200SP CPU 1512SP-1 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1513pro-2 PN, SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1511-1 PN TX RAIL, SIMATIC S7-1500 CPU 1517F-3 PN, SIMATIC S7-1500 CPU 1517F-3 PN/DP, SIMATIC ET 200SP CPU 1512SP-1 PN, SIMATIC ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1516pro-2 PN, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIPLUS S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1513F-1 PN, SIPLUS ET 200SP CPU 1512SP-1 PN RAIL, SIPLUS S7-1500 CPU 1515F-2 PN RAIL, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs, SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN, SIPLUS S7-1500 CPU 1511F-1 PN, SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL, SIPLUS S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1516pro F-2 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 Software Controller Linux V3, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1517-3 PN/DP, SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL, SIPLUS S7-1500 CPU 1515F-2 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1518TF-4 PN/DP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 CPU 1518F-3 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S F V3, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC ET 200SP CPU 1512SP-1 PN, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1516T-3 PN, SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1511-1 PN, SIMATIC S7-PLCSIM Advanced, SIMATIC Drive Controller CPU 1504D TF, SIMATIC S7-1500 CPU 1511T-1 PN, SIPLUS ET 200SP CPU 1512SP F-1 PN, SIMATIC S7-1500 CPU 1518TF-3 PN, SIMATIC Drive Controller CPU 1507D TF, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S V3, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 CPU 1515TF-2 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIMATIC S7-1500 CPU 1511F-1 PN, SIMATIC S7-1500 CPU 1518-4 PN/DP, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC ET 200SP CPU 1514SP-2 PN, SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN, SIMATIC S7-1500 CPU 1513F-1 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs, SIMATIC S7-1500 CPU 1518T-4 PN/DP, SIMATIC S7-1500 Software Controller CPU 1508S F V2, SIPLUS S7-1500 CPU 1511-1 PN, SIMATIC S7-1500 CPU 1518F-4 PN/DP, SIPLUS S7-1500 CPU 1518F-4 PN/DP, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC S7-1500 CPU 1513-1 PN, SIMATIC S7-1500 CPU 1515F-2 PN, SIMATIC S7-1500 CPU 1518T-3 PN, SIMATIC S7-1500 Software Controller CPU 1508S TF V3, SIMATIC S7-1500 CPU 1517-3 PN, SIMATIC S7-1500 CPU 1515F-2 PN, SIPLUS S7-1500 CPU 1513-1 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL, SIPLUS S7-1500 CPU 1516-3 PN/DP, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-1500 CPU 1518-3 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIMATIC ET 200SP CPU 1510SP F-1 PN, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs, SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL, SIMATIC S7-1500 CPU 1513pro F-2 PN, SIPLUS S7-1500 CPU 1516F-3 PN/DP, SIPLUS ET 200SP CPU 1510SP F-1 PN, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC ET 200SP CPU 1510SP-1 PN, SIMATIC S7-1500 Software Controller CPU 1507S F V4, SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC S7-1500 CPU 1515-2 PN, SIMATIC S7-1500 CPU 1516-3 PN/DP, SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL, SIMATIC ET 200SP CPU 1514SPT-2 PN, SIMATIC S7-1500 CPU 1515T-2 PN, SIMATIC S7-1500 CPU 1516TF-3 PN/DP, SIMATIC S7-1500 CPU 1511C-1 PN, SIMATIC S7-1500 CPU 1512C-1 PN, SIMATIC S7-1500 Software Controller CPU 1508S V2, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS ET 200SP CPU 1512SP-1 PN RAIL, SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL, SIMATIC S7-1500 Software Controller CPU 1508S V3, SIMATIC S7-1500 CPU 1516TF-3 PN, SIPLUS ET 200SP CPU 1510SP-1 PN RAIL, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Provider severity
CRITICAL
Conflicts
2

CVE-2026-25785

Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.

PUBLISHED
Vendor
MOTEX Inc.
Product
Lanscope Endpoint Manager (On-Premises) Sub-Manager Server
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25783

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25782

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25781

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

PUBLISHED
Vendor
OpenHarmony
Product
OpenHarmony
Provider severity
HIGH
Conflicts
0

CVE-2026-25780

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2578

Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25779

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25778

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a

PUBLISHED
Vendor
SWITCH EV
Product
swtchenergy.com
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-25776

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

PUBLISHED
Vendor
Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd.
Product
Movable Type, Movable Type, Movable Type, Movable Type Advanced, Movable Type Premium, Movable Type, Movable Type, Movable Type Premium Advanced Edition, Movable Type, Movable Type Premium, Movable Type, Movable Type Premium, Movable Type Premium (MT8-based), Movable Type, Movable Type Advanced, Movable Type Premium Advanced Edition, Movable Type, Movable Type Premium Advanced Edition, Movable Type Advanced, Movable Type Advanced, Movable Type
Provider severity
CRITICAL
Conflicts
2

CVE-2026-25775

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware.

PUBLISHED
Vendor
SenseLive
Product
X3050
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25774

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

PUBLISHED
Vendor
EV Energy
Product
ev.energy
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25773

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reordering categories. An attacker can inject a malicious SQL payload into the category id field, which is stored in the database and later executed unsanitized when the category reorder API processes the stored value. This Second-Order SQL Injection (Time-Based Blind) allows an authenticated attacker to exfiltrate sensitive data including password hash

PUBLISHED
Vendor
Mattermost
Product
Focalboard
Provider severity
HIGH
Conflicts
0

CVE-2026-25772

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.14.3, a stack-based buffer overflow vulnerability exists in the Wazuh Database synchronization module (`wdb_delta_event.c`). The SQL query construction logic allows for an integer underflow when calculating the remaining buffer size. This occurs because the code incorrectly aggregates the return value of `snprintf`. If a specific database synchronization

PUBLISHED
Vendor
wazuh
Product
wazuh
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25771

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 and prior to version 4.14.3, a Denial of Service (DoS) vulnerability exists in the Wazuh API authentication middleware (`middlewares.py`). The application uses an asynchronous event loop (Starlette/Asyncio) to call a synchronous function (`generate_keypair`) that performs blocking disk I/O on every request containing a Bearer token. An unauthenticated remote attacker can exploi

PUBLISHED
Vendor
wazuh
Product
wazuh
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25770

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization protocol. The `wazuh-clusterd` service allows authenticated nodes to write arbitrary files to the manager’s file system with the permissions of the `wazuh` system user. Due to insecure default permissions, the `wazuh` user has write access to the manager's mai

PUBLISHED
Vendor
wazuh
Product
wazuh
Provider severity
CRITICAL
Conflicts
1

CVE-2026-2577

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hijack the WhatsApp session. This allows the attacker to send messages on behalf of the user, intercept all incoming messages and media in real-time, and capture authentication QR codes.

PUBLISHED
Vendor
HKUDS
Product
nanobot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25769

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker architecture) and any organization with a compromised worker node (e.g., through initial access, insider threat, or supply chain attack) are impacted. An attacker who gains access to a worker node (through any means) can achieve

PUBLISHED
Vendor
wazuh
Product
wazuh
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25768

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.

PUBLISHED
Vendor
cloudamqp
Product
lavinmq
Provider severity
HIGH
Conflicts
0

CVE-2026-25767

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user with the "Policymaker" management tag could exploit it to read messages from vhosts they are not authorized to access or publish messages to vhosts they are not authorized to access. This vulnerability is fixed in 2.6.8.

PUBLISHED
Vendor
cloudamqp
Product
lavinmq
Provider severity
HIGH
Conflicts
0

CVE-2026-25766

Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static root. In `middleware/static.go`, the requested path is unescaped and normalized with `path.Clean` (URL semantics). `path.Clean` does not treat `\` as a path separator, so `..\` sequences remain in the cleaned path. The resulting path is then passed to `currentFS.Open(...)

PUBLISHED
Vendor
labstack
Product
echo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25765

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL's host/authority component. This means that if any application passes user-controlled input to Far

PUBLISHED
Vendor
lostisland
Product
faraday
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25764

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The application does not escape HTML tags, an attacker with administrator privileges can create a work package with the name containing the HTML tags and add it to the Work package section when creating time tracking. This issue has been patched in versions 16.6.7 and 17.0.3.

PUBLISHED
Vendor
opf
Product
openproject
Provider severity
LOW
Conflicts
0

CVE-2026-25763

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest changes” view via git log. By supplying a specially crafted rev value (for example, rev=--output=/tmp/poc.txt), an attacker can inject git log command-line options. When OpenProject executes the SCM command, Git interprets the attack

PUBLISHED
Vendor
opf
Product
openproject
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25762

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multipart parser may accumulate an unbounded amount of data in memory while attempting to detect file types, potentially leading to excessive memory consumption and process termination. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.

PUBLISHED
Vendor
adonisjs
Product
core
Provider severity
HIGH
Conflicts
1

CVE-2026-25761

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull request that introduces a file whose name contains shell command substitution syntax, such as $(...). In affected Super-linter versions, runtime scripts may execute the embedded command during file discov

PUBLISHED
Vendor
super-linter
Product
super-linter
Provider severity
HIGH
Conflicts
0

CVE-2026-25760

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose credentials, configs, and keys. This vulnerability is fixed in 1.6.11.

PUBLISHED
Vendor
BishopFox
Product
sliver
Provider severity
MEDIUM
Conflicts
0