Export limit exceeded: 398369 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398369 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16675 | 2 Rockwell Automation, Rockwellautomation | 2 Factorytalk Activation Manager, Factorytalk Activation Manager | 2026-09-01 | N/A |
| A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources. | ||||
| CVE-2026-9625 | 2 Rockwell Automation, Rockwellautomation | 2 Rslinx Classic , Rslinx Classic | 2026-09-01 | N/A |
| A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. | ||||
| CVE-2026-9622 | 2 Rockwell Automation, Rockwellautomation | 2 Rslinx Classic , Rslinx Classic | 2026-09-01 | N/A |
| A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. | ||||
| CVE-2026-9621 | 2 Rockwell Automation, Rockwellautomation | 2 Rslinx Classic , Rslinx Classic | 2026-09-01 | N/A |
| A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover | ||||
| CVE-2026-9637 | 1 Rockwell Automation | 1 Compactlogix 5380 Controllogix 5580 | 2026-09-01 | N/A |
| A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover | ||||
| CVE-2026-9624 | 2 Rockwell Automation, Rockwellautomation | 2 Rslinx Classic , Rslinx Classic | 2026-09-01 | N/A |
| A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover. | ||||
| CVE-2026-84109 | 1 Xinhu | 1 Rainrock Rockoa | 2026-09-01 | 6.3 Medium |
| A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-82551 | 1 Linux Foundation | 1 Magma | 2026-09-01 | 5.3 Medium |
| A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-82228 | 2 Siteground, Wordpress | 2 Siteground Security, Wordpress | 2026-09-01 | 8.1 High |
| Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. | ||||
| CVE-2026-81768 | 2 Highwarden, Wordpress | 2 Super Store Finder, Wordpress | 2026-09-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | ||||
| CVE-2026-81763 | 2 Wordpress, ウェブ屋のさとーさん | 2 Wordpress, Throws Spam Away | 2026-09-01 | 9.3 Critical |
| Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | ||||
| CVE-2026-81780 | 2 Hashthemes, Wordpress | 2 Hash Form, Wordpress | 2026-09-01 | 10 Critical |
| Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | ||||
| CVE-2026-81297 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Forms Pro Add On Pack | 2026-09-01 | 7.5 High |
| Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | ||||
| CVE-2026-81278 | 2 Wordpress, Wpexperts | 2 Wordpress, Post Smtp | 2026-09-01 | 5.4 Medium |
| Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1. | ||||
| CVE-2026-81293 | 2 Passionate Programmer Peter, Wordpress | 2 Wp Data Access, Wordpress | 2026-09-01 | 9.3 Critical |
| Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | ||||
| CVE-2026-82225 | 2 Metagauss, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-01 | 7.4 High |
| Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | ||||
| CVE-2026-81758 | 2 Ownerrez, Wordpress | 2 Ownerrez Api, Wordpress | 2026-09-01 | 6.3 Medium |
| Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | ||||
| CVE-2026-81287 | 2 Syed Balkhi, Wordpress | 2 Charitable, Wordpress | 2026-09-01 | 8.5 High |
| Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. | ||||
| CVE-2026-81280 | 2 Ukr Solution, Wordpress | 2 Print Barcode Labels For Your Woocommerce Products/orders, Wordpress | 2026-09-01 | 6.5 Medium |
| Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | ||||
| CVE-2026-84153 | 1 Xinhu | 1 Rainrock Rockoa | 2026-09-01 | 6.3 Medium |
| A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation of the argument Value can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||