Search

Search Results (371925 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-18007 1 Google 1 Chrome 2026-07-30 N/A
Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-18008 1 Google 1 Chrome 2026-07-30 N/A
Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
CVE-2026-18009 1 Google 1 Chrome 2026-07-30 N/A
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
CVE-2026-18011 1 Google 1 Chrome 2026-07-30 N/A
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Low)
CVE-2026-18013 1 Google 1 Chrome 2026-07-30 N/A
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-18014 1 Google 1 Chrome 2026-07-30 N/A
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
CVE-2026-18015 1 Google 1 Chrome 2026-07-30 N/A
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-18018 1 Google 1 Chrome 2026-07-30 N/A
Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
CVE-2026-18019 1 Google 1 Chrome 2026-07-30 N/A
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-18186 1 Asustor 1 Adm 2026-07-30 N/A
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
CVE-2026-7849 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 9.8 Critical
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
CVE-2026-44108 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 9.8 Critical
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
CVE-2026-44107 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 7.5 High
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
CVE-2026-44105 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 6.6 Medium
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
CVE-2026-44106 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 7.8 High
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
CVE-2026-44104 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 9.8 Critical
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
CVE-2026-44103 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 5.3 Medium
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
CVE-2026-44102 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 5.3 Medium
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
CVE-2026-44101 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 9.8 Critical
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
CVE-2026-44100 1 Phoenix Contact 4 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 1 more 2026-07-30 9.4 Critical
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.