Common Vulnerabilities and Exposures (CVE)

CVE-2026-20270

Oct 2, 2026 23:22:51 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20267

Oct 2, 2026 23:22:41 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20268

Oct 2, 2026 23:22:31 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-105051

Oct 2, 2026 22:59:56 UTC

Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).

CVE-2026-105050

Oct 2, 2026 22:37:54 UTC

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.

CVE-2026-105049

Oct 2, 2026 22:14:36 UTC

Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.

CVE-2026-84411

Oct 2, 2026 22:09:48 UTC

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitr...

CVE-2026-105048

Oct 2, 2026 22:08:31 UTC

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

CVE-2026-94591

Oct 2, 2026 21:54:42 UTC

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the so...

CVE-2026-94592

Oct 2, 2026 21:52:54 UTC

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server o...

CVE-2026-105046

Oct 2, 2026 21:51:34 UTC

Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.

CVE-2026-94593

Oct 2, 2026 21:51:00 UTC

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when...

CVE-2026-94594

Oct 2, 2026 21:48:14 UTC

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the lo...

CVE-2026-95102

Oct 2, 2026 21:34:37 UTC

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. ...

CVE-2026-105043

Oct 2, 2026 21:34:14 UTC

MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.