Export limit exceeded: 372205 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372205 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372205 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-23573 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-31 | 3.7 Low |
| HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack. | ||||
| CVE-2024-23575 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-31 | 5.3 Medium |
| HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack. | ||||
| CVE-2024-23577 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-31 | 4.3 Medium |
| HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations. | ||||
| CVE-2024-23569 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-31 | 4.3 Medium |
| HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | ||||
| CVE-2024-23570 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-31 | 4.3 Medium |
| HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more. | ||||
| CVE-2024-23572 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-31 | 4.2 Medium |
| HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function. | ||||
| CVE-2026-63550 | 1 Mz-automation | 1 Libiec61850 | 2026-07-31 | 6.5 Medium |
| The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service. | ||||
| CVE-2026-66369 | 1 Mz-automation | 1 Libiec61850 | 2026-07-31 | 6.5 Medium |
| The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. | ||||
| CVE-2026-66720 | 1 Mz-automation | 1 Libiec61850 | 2026-07-31 | 6.5 Medium |
| The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. | ||||
| CVE-2026-63033 | 1 Mz-automation | 1 Lib60870 | 2026-07-31 | 6.5 Medium |
| A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. | ||||
| CVE-2026-61893 | 1 Mz-automation | 1 Lib60870 | 2026-07-31 | 6.5 Medium |
| A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. | ||||
| CVE-2026-58039 | 2026-07-31 | N/A | ||
| A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2025-59866 | 1 Hcltech | 3 Dfmpro For Catia, Dfxanalytics, Dfxserver | 2026-07-31 | 3.3 Low |
| The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary. | ||||
| CVE-2026-66360 | 1 Mz-automation | 1 Libiec61850 | 2026-07-31 | 7.5 High |
| The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition. | ||||
| CVE-2026-65421 | 1 Mz-automation | 1 Libiec61850 | 2026-07-31 | 6.5 Medium |
| The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition. | ||||
| CVE-2026-66364 | 1 Mz-automation | 1 Libiec61850 | 2026-07-30 | 6.5 Medium |
| The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition. | ||||
| CVE-2026-62845 | 1 Clastix | 1 Kamaji | 2026-07-30 | 4.7 Medium |
| Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge. | ||||
| CVE-2026-65834 | 1 Projectcapsule | 1 Capsule | 2026-07-30 | 6.8 Medium |
| Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the configuration admission webhook, allowing a Cluster Admin to store a malformed regex that later reached regexp.MustCompile in pkg/api/forbidden_list.go through internal/webhook/node/user_metadata.go and crashed the node admission webhook on Node create, update, or patch requests. This issue is fixed in version 0.13.8. | ||||
| CVE-2026-66349 | 2026-07-30 | 6.5 Medium | ||
| The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition. | ||||
| CVE-2025-69933 | 1 Codeastro | 1 Membership Management System | 2026-07-30 | N/A |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | ||||