|
CVE-2026-80275
|
Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint
|
Comelit Group S.p.A.
|
1456B Multi-User Gateway
|
High
|
8.8
|
2026-10-01 05:51:37 |
Deep Dive
|
|
CVE-2026-80276
|
Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface
|
Comelit Group S.p.A.
|
1456B Multi-User Gateway
|
High
|
7.5
|
2026-10-01 05:51:22 |
Deep Dive
|
|
CVE-2026-103542
|
formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery
|
formtools.org
|
Form Tools
|
Medium
|
4.3
|
2026-10-01 05:45:09 |
Deep Dive
|
|
CVE-2026-88999
|
Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter
|
davidanderson
|
Redux Framework
|
Medium
|
4.3
|
2026-10-01 05:30:56 |
Deep Dive
|
|
CVE-2026-85679
|
Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key
|
extendify
|
Extendify
|
High
|
7.2
|
2026-10-01 05:30:55 |
Deep Dive
|
|
CVE-2026-103541
|
formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload
|
formtools.org
|
Form Tools
|
Medium
|
6.3
|
2026-10-01 05:30:10 |
Deep Dive
|
|
CVE-2026-67075
|
HCL Digital Experience is affected by improper input sanitation
|
HCLSoftware
|
Digital Experience
|
Medium
|
6.5
|
2026-10-01 05:20:51 |
Deep Dive
|
|
CVE-2026-103540
|
formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engine
|
formtools.org
|
Form Tools
|
Medium
|
6.3
|
2026-10-01 05:15:13 |
Deep Dive
|
|
CVE-2026-103539
|
ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication
|
ZongXR
|
SuperMarket
|
Medium
|
5.4
|
2026-10-01 05:00:09 |
Deep Dive
|
|
CVE-2026-82825
|
Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed
|
Hitachi Industrial Equipment Systems
|
Hitachi Coding Software Suite
|
Critical
|
9.8
|
2026-10-01 04:57:58 |
Deep Dive
|
|
CVE-2026-82824
|
Path traversal may allow arbitrary files to be viewed, created, modified, or deleted
|
Hitachi Industrial Equipment Systems
|
Hitachi Coding Software Suite
|
Critical
|
9.8
|
2026-10-01 04:57:58 |
Deep Dive
|
|
CVE-2026-82826
|
Authentication information or sensitive data may be intercepted in transit
|
Hitachi Industrial Equipment Systems
|
Hitachi Coding Software Suite
|
High
|
7.5
|
2026-10-01 04:57:57 |
Deep Dive
|
|
CVE-2026-82827
|
A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens
|
Hitachi Industrial Equipment Systems
|
Hitachi Coding Software Suite
|
Critical
|
9.8
|
2026-10-01 04:57:56 |
Deep Dive
|
|
CVE-2026-82828
|
Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges
|
Hitachi Industrial Equipment Systems
|
Hitachi Coding Software Suite
|
High
|
8.8
|
2026-10-01 04:57:55 |
Deep Dive
|
|
CVE-2026-82829
|
Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process
|
Hitachi Industrial Equipment Systems
|
Hitachi Coding Software Suite
|
Critical
|
9.8
|
2026-10-01 04:57:54 |
Deep Dive
|
|
CVE-2026-76147
|
Genians, Inc Genian NAC/ZTNA Remote Code Execution
|
Genians, Inc
|
Genian NAC 4.0.175 Release
|
Medium
|
5.9
|
2026-10-01 04:53:40 |
Deep Dive
|
|
CVE-2026-76146
|
Genians, Inc Genian SSL PNS OS Command Injection
|
Genians, Inc
|
Genian SSL PNS (xenics_auther)
|
High
|
8.4
|
2026-10-01 04:53:39 |
Deep Dive
|
|
CVE-2026-76145
|
Genians, Inc Genian SSL PNS Improper Privilege Management
|
Genians, Inc
|
Genian SSL PNS (frodo-core)
|
High
|
7.5
|
2026-10-01 04:53:38 |
Deep Dive
|
|
CVE-2026-76143
|
Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass
|
Genians, Inc
|
Genian SSL PNS (frodo-core)
|
High
|
7.3
|
2026-10-01 04:53:37 |
Deep Dive
|
|
CVE-2026-76144
|
Genians, Inc Genian SSL PNS Unrestricted File Upload
|
Genians, Inc
|
Genian SSL PNS (frodo-core)
|
Low
|
1.8
|
2026-10-01 04:53:37 |
Deep Dive
|