Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29528
Total
2302
Critical
8845
High
9186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40461 | HIGH | 7.5 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate … | Apr 17, 2026 |
| CVE-2026-40434 | HIGH | 8.1 | Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt … | Apr 17, 2026 |
| CVE-2026-40342 | CRITICAL | 9.9 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine … | Apr 17, 2026 |
| CVE-2026-40283 | MEDIUM | 6.8 | WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject … | Apr 17, 2026 |
| CVE-2026-40066 | HIGH | 8.8 | Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated … | Apr 17, 2026 |
| CVE-2026-35682 | HIGH | 8.8 | Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level … | Apr 17, 2026 |
| CVE-2026-35546 | CRITICAL | 9.8 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code … | Apr 17, 2026 |
| CVE-2026-35215 | HIGH | 7.5 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of … | Apr 17, 2026 |
| CVE-2026-35061 | MEDIUM | 5.3 | Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operational imagery. | Apr 17, 2026 |
| CVE-2026-34232 | HIGH | 7.5 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type … | Apr 17, 2026 |
| CVE-2026-33569 | MEDIUM | 6.5 | Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise … | Apr 17, 2026 |
| CVE-2026-33516 | UNKNOWN | — | xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when … | Apr 17, 2026 |
| CVE-2026-33093 | MEDIUM | 5.3 | Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual information about … | Apr 17, 2026 |
| CVE-2026-32650 | HIGH | 7.5 | Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling … | Apr 17, 2026 |
| CVE-2026-32648 | MEDIUM | 5.3 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device. | Apr 17, 2026 |
| CVE-2026-32624 | UNKNOWN | — | xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is … | Apr 17, 2026 |
| CVE-2026-32623 | UNKNOWN | — | xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from … | Apr 17, 2026 |
| CVE-2026-32324 | HIGH | 7.7 | Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at … | Apr 17, 2026 |
| CVE-2026-32107 | HIGH | 8.8 | xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop … | Apr 17, 2026 |
| CVE-2026-32105 | UNKNOWN | — | xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted … | Apr 17, 2026 |
| CVE-2026-31927 | MEDIUM | 4.9 | Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when … | Apr 17, 2026 |
| CVE-2026-6437 | MEDIUM | 6.5 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation … | Apr 17, 2026 |
| CVE-2026-40525 | CRITICAL | 9.1 | OpenViking prior to commit c7bb167 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the … | Apr 17, 2026 |
| CVE-2026-33337 | HIGH | 7.5 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does … | Apr 17, 2026 |
| CVE-2026-28224 | HIGH | 8.2 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior … | Apr 17, 2026 |