Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-74994 UNKNOWN The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks … Sep 01, 2026
CVE-2026-74835 UNKNOWN The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP … Sep 01, 2026
CVE-2026-73812 UNKNOWN httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. … Sep 01, 2026
CVE-2026-73276 UNKNOWN Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, … Sep 01, 2026
CVE-2026-73270 UNKNOWN Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting … Sep 01, 2026
CVE-2026-71562 UNKNOWN Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a … Sep 01, 2026
CVE-2026-71380 UNKNOWN Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid … Sep 01, 2026
CVE-2026-70409 UNKNOWN Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral … Sep 01, 2026
CVE-2026-70405 UNKNOWN Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a … Sep 01, 2026
CVE-2026-70399 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and … Sep 01, 2026
CVE-2026-69664 UNKNOWN Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a … Sep 01, 2026
CVE-2026-66835 UNKNOWN Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path … Sep 01, 2026
CVE-2026-66357 UNKNOWN httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a … Sep 01, 2026
CVE-2026-5480 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Sep 01, 2026
CVE-2026-59696 UNKNOWN Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component … Sep 01, 2026
CVE-2026-58569 HIGH 8.8 Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute … Sep 01, 2026
CVE-2026-55951 UNKNOWN The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults … Sep 01, 2026
CVE-2026-18780 HIGH 7.1 Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects … Sep 01, 2026
CVE-2026-18771 HIGH 7.5 Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft … Sep 01, 2026
CVE-2026-18630 HIGH 8.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software … Sep 01, 2026
CVE-2026-9637 UNKNOWN A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length … Sep 01, 2026
CVE-2026-9634 UNKNOWN A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one … Sep 01, 2026
CVE-2026-9633 UNKNOWN A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one … Sep 01, 2026
CVE-2026-9625 UNKNOWN A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to … Sep 01, 2026
CVE-2026-9624 UNKNOWN A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length … Sep 01, 2026