Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56907
Total
4512
Critical
16897
High
16715
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84408 | HIGH | 8.8 | QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC … | Sep 16, 2026 |
| CVE-2026-81326 | MEDIUM | 5.5 | QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client … | Sep 16, 2026 |
| CVE-2026-27565 | CRITICAL | 9.8 | An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active … | Sep 16, 2026 |
| CVE-2026-27564 | HIGH | 7.2 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of … | Sep 16, 2026 |
| CVE-2026-27563 | HIGH | 7.2 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution … | Sep 16, 2026 |
| CVE-2026-27562 | HIGH | 7.2 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution … | Sep 16, 2026 |
| CVE-2026-27561 | HIGH | 7.2 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution … | Sep 16, 2026 |
| CVE-2026-27560 | HIGH | 7.2 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution … | Sep 16, 2026 |
| CVE-2026-27559 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution … | Sep 16, 2026 |
| CVE-2026-27558 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on … | Sep 16, 2026 |
| CVE-2026-27557 | HIGH | 7.5 | An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read. | Sep 16, 2026 |
| CVE-2026-27556 | HIGH | 8.8 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP … | Sep 16, 2026 |
| CVE-2026-27555 | HIGH | 8.8 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP … | Sep 16, 2026 |
| CVE-2026-27554 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on … | Sep 16, 2026 |
| CVE-2026-27553 | MEDIUM | 6.5 | A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password … | Sep 16, 2026 |
| CVE-2026-27552 | HIGH | 8.1 | A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing … | Sep 16, 2026 |
| CVE-2026-27551 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on … | Sep 16, 2026 |
| CVE-2026-27550 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on … | Sep 16, 2026 |
| CVE-2026-27549 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on … | Sep 16, 2026 |
| CVE-2026-27548 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root … | Sep 16, 2026 |
| CVE-2026-27547 | HIGH | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with … | Sep 16, 2026 |
| CVE-2026-27546 | CRITICAL | 9.8 | An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. | Sep 16, 2026 |
| CVE-2026-8030 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2026-86475 | MEDIUM | 5.3 | The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, … | Sep 16, 2026 |
| CVE-2026-84906 | MEDIUM | 5.3 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the … | Sep 16, 2026 |