Total CVEs

150,798

Critical Severity

4,991

High Severity

17,614

Last 7 Days

2,056
Quick preset (or use dates below)
Clear Filters
Showing 1,921 - 1,940 of 150,798 CVEs

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BAC...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request wit...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `pr...

Vendor: Loytec
Product: LWEB-802
Published: Jul 24, 2026
Source: NVD

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.

Vendor: Loytec
Product: LWEB-802
Published: Jul 24, 2026
Source: NVD

Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an o...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD
CVE-2026-49326 MEDIUM - 6.5

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored ...

Vendor: Apache Software Foundation
Product: Apache HBase
Published: Jul 24, 2026
Source: NVD
CVE-2026-17059 MEDIUM - 6.5

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a ...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7
Published: Jul 24, 2026
Source: NVD
CVE-2026-16802 MEDIUM - 6.5

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

Vendor: Devolutions
Product: PowerShell Universal
Published: Jul 24, 2026
Source: NVD
CVE-2026-16801 HIGH - 8.8

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly esc...

Vendor: Devolutions
Product: PowerShell Universal
Published: Jul 24, 2026
Source: NVD
CVE-2026-16800 HIGH - 8.8

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated i...

Vendor: Devolutions
Product: PowerShell Universal
Published: Jul 24, 2026
Source: NVD
CVE-2026-16799 MEDIUM - 5.0

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

Vendor: Devolutions
Product: PowerShell Universal
Published: Jul 24, 2026
Source: NVD
CVE-2026-16798 MEDIUM - 6.5

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to st...

Vendor: Devolutions
Product: PowerShell Universal
Published: Jul 24, 2026
Source: NVD

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an em...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacki...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD
CVE-2026-17048 MEDIUM - 5.5

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permi...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7
Published: Jul 24, 2026
Source: NVD

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Ro...

Vendor: npm
Product: react-router
Published: Jul 24, 2026
Source: GitHub
CVE-2026-9765 HIGH - 7.1

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized a...

Published: Jul 24, 2026
Source: NVD
CVE-2026-7484 MEDIUM - 5.3

External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: before 202606251646.

Published: Jul 24, 2026
Source: NVD