Export limit exceeded: 374340 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374340 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (6 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-11425 | 1 Domoticz | 1 Domoticz | 2026-08-07 | 4.4 Medium |
| Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator's browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover. | ||||
| CVE-2026-71265 | 1 Domoticz | 1 Domoticz | 2026-08-05 | 7.5 High |
| Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy() with no length check, across three separate code branches (DS10A/KR10A/MS10A device types). An attacker on the local network segment able to reach the Mochad TCP bridge (default port 1099, no authentication) can send a crafted packet that overflows tempRFSECbuf by up to several hundred bytes, corrupting the Domoticz worker thread's stack. | ||||
| CVE-2026-1001 | 1 Domoticz | 1 Domoticz | 2026-04-02 | 4.8 Medium |
| Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context. | ||||
| CVE-2019-15480 | 1 Domoticz | 1 Domoticz | 2024-11-21 | N/A |
| Domoticz 4.10717 has XSS via item.Name. | ||||
| CVE-2019-10678 | 1 Domoticz | 1 Domoticz | 2024-11-21 | N/A |
| Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options. | ||||
| CVE-2019-10664 | 1 Domoticz | 1 Domoticz | 2024-11-21 | N/A |
| Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp. | ||||
Page 1 of 1.