Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74994 | UNKNOWN | — | The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks … | Sep 01, 2026 |
| CVE-2026-74835 | UNKNOWN | — | The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP … | Sep 01, 2026 |
| CVE-2026-73812 | UNKNOWN | — | httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. … | Sep 01, 2026 |
| CVE-2026-73276 | UNKNOWN | — | Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, … | Sep 01, 2026 |
| CVE-2026-73270 | UNKNOWN | — | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting … | Sep 01, 2026 |
| CVE-2026-71562 | UNKNOWN | — | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a … | Sep 01, 2026 |
| CVE-2026-71380 | UNKNOWN | — | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid … | Sep 01, 2026 |
| CVE-2026-70409 | UNKNOWN | — | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral … | Sep 01, 2026 |
| CVE-2026-70405 | UNKNOWN | — | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a … | Sep 01, 2026 |
| CVE-2026-70399 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and … | Sep 01, 2026 |
| CVE-2026-69664 | UNKNOWN | — | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a … | Sep 01, 2026 |
| CVE-2026-66835 | UNKNOWN | — | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path … | Sep 01, 2026 |
| CVE-2026-66357 | UNKNOWN | — | httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a … | Sep 01, 2026 |
| CVE-2026-5480 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | Sep 01, 2026 |
| CVE-2026-59696 | UNKNOWN | — | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component … | Sep 01, 2026 |
| CVE-2026-58569 | HIGH | 8.8 | Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute … | Sep 01, 2026 |
| CVE-2026-55951 | UNKNOWN | — | The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults … | Sep 01, 2026 |
| CVE-2026-18780 | HIGH | 7.1 | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects … | Sep 01, 2026 |
| CVE-2026-18771 | HIGH | 7.5 | Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft … | Sep 01, 2026 |
| CVE-2026-18630 | HIGH | 8.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software … | Sep 01, 2026 |
| CVE-2026-9637 | UNKNOWN | — | A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length … | Sep 01, 2026 |
| CVE-2026-9634 | UNKNOWN | — | A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one … | Sep 01, 2026 |
| CVE-2026-9633 | UNKNOWN | — | A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one … | Sep 01, 2026 |
| CVE-2026-9625 | UNKNOWN | — | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to … | Sep 01, 2026 |
| CVE-2026-9624 | UNKNOWN | — | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length … | Sep 01, 2026 |