Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-0498

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

PUBLISHED
Vendor
SAP_SE
Product
SAP S/4HANA (Private Cloud and On-Premise)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-0497

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
Business Server Pages Application (Product Designer Web UI)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0496

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori App (Intercompany Balance Reconciliation)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0495

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori App (Intercompany Balance Reconciliation)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0494

Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori App (Intercompany Balance Reconciliation)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0493

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on behalf of an authenticated user causing low impact on integrity of the system. This has no impact on confidentiality and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori App (Intercompany Balance Reconciliation)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0492

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system�s confidentiality, integrity, and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP HANA database
Provider severity
HIGH
Conflicts
0

CVE-2026-0491

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

PUBLISHED
Vendor
SAP_SE
Product
SAP Landscape Transformation
Provider severity
CRITICAL
Conflicts
0

CVE-2026-0490

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high impact on the availability but no impact on the confidentiality and integrity.

PUBLISHED
Vendor
SAP_SE
Product
SAP BusinessObjects BI Platform
Provider severity
HIGH
Conflicts
0

CVE-2026-0489

Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on the confidentiality and integrity of the application with no impact on availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Business One (Job Service)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0488

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP CRM and SAP S/4HANA (Scripting Editor)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-0487

SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.

PUBLISHED
Vendor
SAP_SE
Product
SAProuter on Microsoft Windows
Provider severity
HIGH
Conflicts
0

CVE-2026-0486

In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.

PUBLISHED
Vendor
SAP_SE
Product
ABAP based SAP systems
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0485

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering the CMS completely unavailable. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

PUBLISHED
Vendor
SAP_SE
Product
SAP BusinessObjects BI Platform
Provider severity
HIGH
Conflicts
0

CVE-2026-0484

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no effect on the confidentiality and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver Application Server ABAP and SAP S/4HANA
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0483

Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the application. The vulnerability allows arbitrary JavaScript code to be executed in the user's local context.

PUBLISHED
Vendor
LiveHelperChat
Product
LiveHelperChat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0481

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability

PUBLISHED
Vendor
AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD
Product
AMD Instinct™ MI325X, AMD Instinct™ MI355X, AMD Instinct™ MI250, AMD Instinct™ MI210, AMD Instinct™ MI300A, AMD Instinct™ MI308X, AMD Instinct™ MI250X, AMD Instinct™ MI350X, AMD Instinct™ MI300X
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0466

Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.

PUBLISHED
Vendor
AMD
Product
AMD µProf
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0438

A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM, potentially compromising the system’s confidentiality, integrity, and availability.

PUBLISHED
Vendor
AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD
Product
AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors, AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 8000 Series Desktop Processors (formerly codenamed "Phoenix"), AMD Ryzen™ Z2 Series Processors, AMD Ryzen™ 7000 Series Desktop Processors, AMD Ryzen™ 7000 Series Desktop Processors, AMD Ryzen™ Threadripper™ PRO 9000 WX-Series Processors, AMD Ryzen™ 8000 Series Desktop Processors, AMD Ryzen™ Embedded 7000 Series Processors, AMD Ryzen™ 8000 Series Desktop Processors, AMD Ryzen™ AI 300 Series Processors, AMD Ryzen™ Embedded 9000 Series Processors, AMD Ryzen™ Embedded 8000 Series Processors, AMD Ryzen™ 9000 Series Desktop Processors, AMD Ryzen™ 9000HX Series Processors, AMD EPYC™ 4004 Series Processors, AMD Ryzen™ 7000 Series Desktop Processors (formerly codenamed "Raphael"), AMD Ryzen™ Z1 Series Processors, AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors, AMD Ryzen™ AI Max 300 Series Processors, AMD Ryzen™ 7000 Series Desktop Processors, AMD Ryzen™ Z1 Series Processors, AMD Ryzen™ Z2 Series Processors Extreme, AMD Ryzen™ 9000 Series Desktop Processors (formerly codenamed "Granite Ridge"), AMD EPYC™ 4005 Series Processors, AMD Ryzen™ Threadripper™ 7000 Processors, AMD Ryzen™ Threadripper™ 9000 Processors, AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0432

Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.

PUBLISHED
Vendor
AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD
Product
AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors, AMD EPYC™ Embedded 8004 Series Processors, AMD Ryzen™ Threadripper™ 7000 Processors, AMD Ryzen™ Embedded 9000 Series Processors, AMD EPYC™ 9V64H Processor, AMD Ryzen™ 5000 Series Desktop Processors, AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics, AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors, AMD Ryzen™ Embedded V2000 Series Processors, AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics, AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics, AMD Instinct™ MI300A Series Processors, AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics, AMD Ryzen™ 3000 Series Desktop Processors, AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors, AMD EPYC™ Embedded 9005 Series Processors, AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics, AMD EPYC™ 7003 Series Processors, AMD EPYC™ 9004 Series Processors, AMD EPYC™ 9005 Series Processors, AMD Ryzen™ Embedded V1000 Series Processors (formerly codenamed "Raven Ridge"), AMD EPYC™ 8004 Series Processors, AMD Ryzen™ Embedded R2000 Series Processors, AMD Ryzen™ AI Max 300 Series Processors, AMD EPYC™ 7002 Series Processors, AMD Ryzen™ 9000HX Series Processors, AMD Ryzen™ 8000 Series Desktop Processors, AMD Ryzen™ Embedded R1000 Series Processors, AMD EPYC™ 4005 Series Processors, AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors, AMD EPYC™ 4004 Series Processors, AMD Ryzen™ 7000 Series Desktop Processors, AMD Ryzen™ 3000 Series Desktop Processors, AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics, AMD Ryzen™ Embedded 7000 Series Processors, AMD Ryzen™ Threadripper™ 3000 Processors, AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics, AMD Ryzen™ 9000 Series Desktop Processors, AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors, AMD Ryzen™ AI 300 Series Processors, AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics, AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics, AMD EPYC™ 7001 Series Processors, AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 4000 Series Desktop Processors, AMD Ryzen™ AI 400 Series Processors, AMD Ryzen™ Embedded 8000 Series Processors, AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics
Provider severity
HIGH
Conflicts
1

CVE-2026-0428

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGS to write invalid data to a remote Die, potentially resulting in unexpected behavior.

PUBLISHED
Vendor
AMD, AMD, AMD, AMD
Product
AMD Instinct™ MI308X, AMD Instinct™ MI300X, AMD Instinct™ MI325X, AMD Instinct™ MI300A
Provider severity
LOW
Conflicts
1

CVE-2026-0427

Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, integrity, or availability.

PUBLISHED
Vendor
AMD, AMD, AMD, AMD
Product
AMD Instinct™ MI325X, AMD Instinct™ MI300X, AMD Radeon™ PRO V710, AMD Instinct™ MI210
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0421

A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.

PUBLISHED
Vendor
Lenovo, Lenovo, Lenovo, Lenovo
Product
ThinkPad L13 Gen 6 2 in 1 BIOS, ThinkPad L14 Gen 6 BIOS, ThinkPad L16 Gen 2 BIOS, ThinkPad L13 Gen 6 BIOS
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-0420

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RAX120v1, RAX38, RAX120v2, RAX35, RAX40
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emul

PUBLISHED
Vendor
NETGEAR
Product
JR6150
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0418

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBS850, MR80, RAX45, EX6120, RAX40v2, RAX80, MS80, EX6130, RBR750, RAX200, CBR750, RBRE960, RAX20, RS700, RBS840, RAX35v2, RAX50, RBSE960, MS70, RAX42, RBR840, RBR850, RAX38v2, MR70, RBS750, RAXE500, MR60, RAXE450, RAX43, RAX75, RAX50S, MS60, RAX15, RAX48, XR1000
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0417

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
XR1000, R7000, RAX20, RAX42, R8000P, MS60, RAX50S, MR60, RAX40v2, R6400v2, RAX43, R8500, RAX50, RAX45, RAXE450, RAX48, RAX35v2, MR80, RAX41, R6700v3, MS70, MR70, R6900P, RAXE500, MS80, R7000P, R7960P
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0416

An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.

PUBLISHED
Vendor
NETGEAR, NETGEAR
Product
RAXE500, RAXE450
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0415

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBS860, RBR850, RBR840, RBRE950, RBS840, RBR750, RBS750, RBSE960, RBS850, RBRE960, RBE970, RBSE950, RBR860
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0414

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

PUBLISHED
Vendor
NETGEAR
Product
RBE970
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0413

A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBS840, RBR840, RBSE960, RBS860, RBR860, RBRE960, RBR850, RBE770, RBS750, RBS850, RBE370, RBR750, RBSE950, RBRE950
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0412

Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no longer receiving security updates. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability

PUBLISHED
Vendor
NETGEAR
Product
JR6150
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0411

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBR760, RBR350, RBE970, RBS760, RBS350
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0410

Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RAXE450, RAX42, RAX35v2, XR1000, RAX43, RAX42v2, XR1000v2, RAX50S, RAX49S, RAX41v2, RAX20, RAX50v2, RAXE500, RAX50, RAX43v2, R7000, RAX54Sv2, RAX54v2, RAX45, RAX41
Provider severity
LOW
Conflicts
1

CVE-2026-0409

A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.

PUBLISHED
Vendor
NETGEAR
Product
Orbi 370
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0408

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
EX2800, EX5000, EX6110, EX3110
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0407

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
EX3110, EX6110, EX2800, EX5000
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0406

An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.

PUBLISHED
Vendor
NETGEAR
Product
XR1000v2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0405

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBE970, RBE773, RBE373, RBE374, NBR750, RBR840, RBS850, RBE771, RBS750, RBE971, RBR750, RBRE950, RBSE950, RBE370, RBE372, RBSE960, RBR860, RBE770, RBE371, RBE772, RBRE960, CBR750, RBR850, RBS860, RBS840
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0404

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBR850, RBS850, RBSE950, RBR750, RBRE950, RBR860, RBS860, RBS750, RBRE960, RBSE960, RBS840, RBR840
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0403

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBS750, RBR750, RBR850, RBS860, RBR860, RBS850, RBRE960, RBSE960, RBE970, RBE971
Provider severity
LOW
Conflicts
1

CVE-2026-0402

A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0401

A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0400

A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0399

Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0398

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

PUBLISHED
Vendor
PowerDNS
Product
Recursor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0397

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy.

PUBLISHED
Vendor
PowerDNS
Product
DNSdist
Provider severity
LOW
Conflicts
1

CVE-2026-0396

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

PUBLISHED
Vendor
PowerDNS
Product
DNSdist
Provider severity
LOW
Conflicts
1

CVE-2026-0394

When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed versi

PUBLISHED
Vendor
Open-Xchange GmbH
Product
OX Dovecot Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0393

The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.

PUBLISHED
Vendor
CODESYS
Product
Visualization
Provider severity
MEDIUM
Conflicts
0