Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56820
Total
4503
Critical
16867
High
16681
Medium
CVE ID Severity Score Description Published
CVE-2026-73173 UNKNOWN — Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that … Sep 16, 2026
CVE-2026-73172 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service … Sep 16, 2026
CVE-2026-73171 UNKNOWN — Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 … Sep 16, 2026
CVE-2026-73170 UNKNOWN — Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in … Sep 16, 2026
CVE-2026-73169 UNKNOWN — Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech … Sep 16, 2026
CVE-2026-73167 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73166 UNKNOWN — Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware … Sep 16, 2026
CVE-2026-73165 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73164 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73163 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-19535 UNKNOWN — Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that … Sep 16, 2026
CVE-2026-92465 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects … Sep 16, 2026
CVE-2026-92463 MEDIUM 6.5 yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list … Sep 16, 2026
CVE-2026-92462 MEDIUM 6.5 yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers … Sep 16, 2026
CVE-2026-92461 MEDIUM 4.3 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers … Sep 16, 2026
CVE-2026-92460 MEDIUM 6.5 yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can … Sep 16, 2026
CVE-2026-92459 MEDIUM 6.5 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission … Sep 16, 2026
CVE-2026-92458 MEDIUM 4.3 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can … Sep 16, 2026
CVE-2026-92457 MEDIUM 6.5 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call … Sep 16, 2026
CVE-2026-92456 HIGH 7.1 yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide … Sep 16, 2026
CVE-2026-92455 MEDIUM 4.3 yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email … Sep 16, 2026
CVE-2026-58147 UNKNOWN — WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements … Sep 16, 2026
CVE-2026-58146 UNKNOWN — WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST … Sep 16, 2026
CVE-2026-40857 UNKNOWN — WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value … Sep 16, 2026
CVE-2026-40856 UNKNOWN — WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It … Sep 16, 2026