Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-73164 — Advantech EKI-1242IEIMS OS Command Injection Vulnerability

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-124…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.6 HIGH
CVE-2026-73163 — Advantech EKI-1242IEIMS OS Command Injection Vulnerability

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-124…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.6 HIGH
CVE-2026-19535 — Advantech EKI-1242IEIMS Cross-Site Request Forgery Vulnerability

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows…

Remote | Cross-Site Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-92360 — ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validat…

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipul…

| Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.6 HIGH
CVE-2026-92465 — WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a throu…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92463 — yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User List…

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92462 — yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-92461 — yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. …

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92460 — yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Att…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92459 — yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without prop…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-92458 — yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attacker…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92457 — yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attac…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92456 — yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoin…

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installat…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-92455 — yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary c…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.3 CRITICAL
CVE-2026-58147 — Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU…

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in t…

| Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.4 CRITICAL
CVE-2026-58146 — Unauthorized remote code execution in T-Mobile 5G Box IDU routers

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST paramete…

| Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.4 HIGH
CVE-2026-40857 — CSRF token bypass in T-Mobile 5G Box IDU routers

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accept…

| Cross-Site Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-40856 — Config disclosure in T-Mobile 5G Box IDU routers

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote atta…

| Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.3 CRITICAL
CVE-2026-40855 — Command Injection in T-Mobile 5G Box IDU router via ping functionality

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, pi…

| Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.7 HIGH
CVE-2026-40854 — Session auth bypass via cookie value in T-Mobile 5G Box IDU routers

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking fo…

| Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
Showing 20 of 14640 Results