Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 43

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-80275 Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint Comelit Group S.p.A. 1456B Multi-User Gateway High 8.8 2026-10-01 05:51:37 Deep Dive
CVE-2026-80276 Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface Comelit Group S.p.A. 1456B Multi-User Gateway High 7.5 2026-10-01 05:51:22 Deep Dive
CVE-2026-103542 formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery formtools.org Form Tools Medium 4.3 2026-10-01 05:45:09 Deep Dive
CVE-2026-88999 Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter davidanderson Redux Framework Medium 4.3 2026-10-01 05:30:56 Deep Dive
CVE-2026-85679 Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key extendify Extendify High 7.2 2026-10-01 05:30:55 Deep Dive
CVE-2026-103541 formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload formtools.org Form Tools Medium 6.3 2026-10-01 05:30:10 Deep Dive
CVE-2026-67075 HCL Digital Experience is affected by improper input sanitation HCLSoftware Digital Experience Medium 6.5 2026-10-01 05:20:51 Deep Dive
CVE-2026-103540 formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engine formtools.org Form Tools Medium 6.3 2026-10-01 05:15:13 Deep Dive
CVE-2026-103539 ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication ZongXR SuperMarket Medium 5.4 2026-10-01 05:00:09 Deep Dive
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed Hitachi Industrial Equipment Systems Hitachi Coding Software Suite Critical 9.8 2026-10-01 04:57:58 Deep Dive
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted Hitachi Industrial Equipment Systems Hitachi Coding Software Suite Critical 9.8 2026-10-01 04:57:58 Deep Dive
CVE-2026-82826 Authentication information or sensitive data may be intercepted in transit Hitachi Industrial Equipment Systems Hitachi Coding Software Suite High 7.5 2026-10-01 04:57:57 Deep Dive
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens Hitachi Industrial Equipment Systems Hitachi Coding Software Suite Critical 9.8 2026-10-01 04:57:56 Deep Dive
CVE-2026-82828 Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges Hitachi Industrial Equipment Systems Hitachi Coding Software Suite High 8.8 2026-10-01 04:57:55 Deep Dive
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process Hitachi Industrial Equipment Systems Hitachi Coding Software Suite Critical 9.8 2026-10-01 04:57:54 Deep Dive
CVE-2026-76147 Genians, Inc Genian NAC/ZTNA Remote Code Execution Genians, Inc Genian NAC 4.0.175 Release Medium 5.9 2026-10-01 04:53:40 Deep Dive
CVE-2026-76146 Genians, Inc Genian SSL PNS OS Command Injection Genians, Inc Genian SSL PNS (xenics_auther) High 8.4 2026-10-01 04:53:39 Deep Dive
CVE-2026-76145 Genians, Inc Genian SSL PNS Improper Privilege Management Genians, Inc Genian SSL PNS (frodo-core) High 7.5 2026-10-01 04:53:38 Deep Dive
CVE-2026-76143 Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass Genians, Inc Genian SSL PNS (frodo-core) High 7.3 2026-10-01 04:53:37 Deep Dive
CVE-2026-76144 Genians, Inc Genian SSL PNS Unrestricted File Upload Genians, Inc Genian SSL PNS (frodo-core) Low 1.8 2026-10-01 04:53:37 Deep Dive