Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16675 | UNKNOWN | — | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows … | Sep 01, 2026 |
| CVE-2026-13348 | UNKNOWN | — | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an … | Sep 01, 2026 |
| CVE-2026-13337 | UNKNOWN | — | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is … | Sep 01, 2026 |
| CVE-2026-13336 | UNKNOWN | — | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands … | Sep 01, 2026 |
| CVE-2026-12663 | UNKNOWN | — | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary … | Sep 01, 2026 |
| CVE-2026-12661 | UNKNOWN | — | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, … | Sep 01, 2026 |
| CVE-2025-12768 | UNKNOWN | — | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the … | Sep 01, 2026 |
| CVE-2024-14047 | HIGH | 7.2 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with … | Sep 01, 2026 |
| CVE-2024-10085 | UNKNOWN | — | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large … | Sep 01, 2026 |
| CVE-2026-84235 | UNKNOWN | — | A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device … | Sep 01, 2026 |
| CVE-2026-84149 | UNKNOWN | — | This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit … | Sep 01, 2026 |
| CVE-2026-84148 | UNKNOWN | — | This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this … | Sep 01, 2026 |
| CVE-2026-84147 | UNKNOWN | — | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker … | Sep 01, 2026 |
| CVE-2026-84145 | HIGH | 7.5 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another … | Sep 01, 2026 |
| CVE-2026-84144 | UNKNOWN | — | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and … | Sep 01, 2026 |
| CVE-2026-84143 | UNKNOWN | — | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another … | Sep 01, 2026 |
| CVE-2026-84142 | UNKNOWN | — | Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with … | Sep 01, 2026 |
| CVE-2026-84141 | UNKNOWN | — | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84140 | UNKNOWN | — | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84139 | UNKNOWN | — | Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84138 | UNKNOWN | — | Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | Sep 01, 2026 |
| CVE-2026-84137 | UNKNOWN | — | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84136 | UNKNOWN | — | Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84135 | UNKNOWN | — | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. | Sep 01, 2026 |
| CVE-2026-84134 | UNKNOWN | — | Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |