Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-10731 — SQL injection in Nemon products

SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be a…

Remote | Injection
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2026-46749 — Siemens SINEC INS Insufficient Password Hashing Strength

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all us…

sinec_ins | Cryptography
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2026-46748 — SINEC INS Local Privilege Escalation via CAP_DAC_OVERRIDE

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability all…

sinec_ins | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2026-46747 — Siemens SINEC INS Path Traversal

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used fo…

sinec_ins | Path Traversal
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2026-46746 — Siemens SINEC INS Command Injection

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injectio…

sinec_ins | Injection
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2026-24349 — SIMATIC WinCC Unified PC Runtime Certificate Manager Information Disclosure

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), S…

| Cryptography
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2025-40808 — Siemens SIPROTEC 5 Arbitrary File Upload

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All version…

Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
0.0 NA
CVE-2026-9698 — DBI versions before 1.648 for Perl saved errors in a limited-sized buffer

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer wit…

| Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
7.6 HIGH
CVE-2026-5068 — bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf…

| Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
8.7 HIGH
CVE-2026-44083 — QuMagie

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have …

qumagie | Remote | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
2.4 LOW
CVE-2026-41986 — ACME File System Logic Bypass Denial of Service

Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.1 MEDIUM
CVE-2026-41985 — Package Management Module Use-After-Free Vulnerability

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

harmonyos | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.2 MEDIUM
CVE-2026-41984 — Vendor Package Manager Use-After-Free

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

harmonyos | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
4.3 MEDIUM
CVE-2026-41983 — Browser Kernel DoS Vulnerability

DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Remote | Denial of Service
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
6.4 MEDIUM
CVE-2026-41982 — [Vendor] IPC Module Race Condition Denial-of-Service

Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Remote | Race Condition
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.3 MEDIUM
CVE-2026-41981 — IPC Module Out-of-Bounds Write Vulnerability

Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.0 MEDIUM
CVE-2026-41977 — Log Service Denial of Service Vulnerability

DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Denial of Service
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
6.6 MEDIUM
CVE-2026-41976 — Google Android Audio Framework Information Disclosure

Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

emui harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
3.6 LOW
CVE-2026-41974 — ServiceNow Notification Permission Control Vulnerability

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.9 MEDIUM
CVE-2026-41973 — Veeam Agent for Linux Access Control Vulnerability

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
Showing 20 of 6989 Results