Export limit exceeded: 394922 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 394922 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (394922 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82771 | 1 Contec | 3 Ece1000, Ece1020, Ecs1020 | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-54626 | 2026-09-17 | 9.8 Critical | ||
| SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel SAIL_PIXEL_FORMAT_BPP8_INDEXED format returned by tga_private_sail_pixel_format() in src/sail-codecs/tga/helpers.c, while sail_codec_load_frame_v8_tga() in src/sail-codecs/tga/tga.c derives a two-to-four-byte pixel_size from an attacker-controlled header bpp value from 9 through 32. Loading a crafted color-mapped run-length-encoded TGA through sail_load_from_file() or sail_load_from_memory() therefore writes attacker-controlled bytes beyond the heap pixel buffer. The pixel-count clamp added for CVE-2026-40494 does not constrain the per-pixel write width, so this issue is an incomplete fix of that vulnerability and can cause heap corruption, a reliable crash, or potential code execution. This issue is fixed in version 1.0.0. | ||||
| CVE-2026-82773 | 1 Contec | 4 M2m Controller Configurable Type Cps-mcs341*, M2m Controller Integrated Type Cps-mc341, M2m Gateway Configurable Type Cps-mgs341* and 1 more | 2026-09-17 | 6.1 Medium |
| Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82774 | 1 Contec | 4 M2m Controller Configurable Type Cps-mcs341*, M2m Controller Integrated Type Cps-mc341, M2m Gateway Configurable Type Cps-mgs341* and 1 more | 2026-09-17 | 8.8 High |
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||||
| CVE-2026-82775 | 1 Contec | 4 M2m Controller Configurable Type Cps-mcs341*, M2m Controller Integrated Type Cps-mc341, M2m Gateway Configurable Type Cps-mgs341* and 1 more | 2026-09-17 | 4.3 Medium |
| An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | ||||
| CVE-2026-82776 | 1 Contec | 2 Configurable Type Cps-pcs341-ds1-1201, Integrated Type Cps-pc341-*-9201 | 2026-09-17 | 6.1 Medium |
| Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82777 | 1 Contec | 2 Configurable Type Cps-pcs341-ds1-1201, Integrated Type Cps-pc341-*-9201 | 2026-09-17 | 8.8 High |
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||||
| CVE-2026-82778 | 1 Contec | 2 Configurable Type Cps-pcs341-ds1-1201, Integrated Type Cps-pc341-*-9201 | 2026-09-17 | 4.3 Medium |
| An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | ||||
| CVE-2026-82781 | 1 Contec | 3 Programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041, Remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1, Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82782 | 1 Contec | 3 Programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041, Remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1, Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 4.3 Medium |
| Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | ||||
| CVE-2026-82783 | 1 Contec | 3 Programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041, Remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1, Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 4.2 Medium |
| Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials. | ||||
| CVE-2026-82784 | 1 Contec | 1 Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 6.5 Medium |
| Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output. | ||||
| CVE-2026-82785 | 1 Contec | 1 Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 4.3 Medium |
| Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | ||||
| CVE-2026-82786 | 1 Contec | 1 Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 6.3 Medium |
| Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file. | ||||
| CVE-2026-82788 | 1 Contec | 1 Cpsl-08p1en | 2026-09-17 | 6.1 Medium |
| Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82787 | 1 Contec | 1 Cpsl-08p1en | 2026-09-17 | 9.8 Critical |
| Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication. | ||||
| CVE-2026-82763 | 1 Contec | 14 Fxa3000, Fxa3020, Fxa3200 and 11 more | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82790 | 1 Contec | 2 Pc-helper Wireless I/o Dio-0404ry-lwf, Pc-helper Wireless I/o Dio-0404ry-lwf-us | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82791 | 1 Contec | 2 Can-2-usb, Can-2-wf | 2026-09-17 | 8.8 High |
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||||
| CVE-2026-82792 | 1 Contec | 2 Can-2-usb, Can-2-wf | 2026-09-17 | 5.2 Medium |
| Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||