Csaf
by Cisagov
Source repositories
CVEs (129)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82583 | Hig | 0.54 | 8.3 | 0.00 | Sep 11, 2026 | NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition. | ||
| CVE-2026-42941 | Hig | 0.54 | 8.3 | 0.00 | May 29, 2026 | The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. | ||
| CVE-2026-42929 | Hig | 0.54 | 8.3 | 0.00 | May 29, 2026 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. | ||
| CVE-2026-90456 | Cri | 0.53 | — | 0.00 | Sep 11, 2026 | An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials… | ||
| CVE-2026-87020 | Hig | 0.53 | 8.1 | 0.01 | Sep 11, 2026 | An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG. | ||
| CVE-2026-78224 | Hig | 0.53 | 8.2 | 0.00 | Sep 11, 2026 | The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. | ||
| CVE-2026-18164 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state. | ||
| CVE-2026-18844 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully… | ||
| CVE-2026-31928 | Hig | 0.53 | 8.1 | 0.01 | Jun 26, 2026 | The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access. | ||
| CVE-2026-50101 | Hig | 0.53 | 8.1 | 0.00 | Jun 12, 2026 | Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any… | ||
| CVE-2026-24790 | Hig | 0.53 | 8.2 | 0.00 | Feb 20, 2026 | The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication. | ||
| CVE-2026-77974 | Hig | 0.52 | 8.0 | 0.00 | Sep 9, 2026 | After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel. | ||
| CVE-2025-12659 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2026 | Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. | ||
| CVE-2025-49848 | Hig | 0.51 | 7.8 | 0.00 | Jun 17, 2025 | An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of… | ||
| CVE-2026-90444 | Hig | 0.50 | — | 0.00 | Sep 11, 2026 | A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed… | ||
| CVE-2026-50245 | Hig | 0.50 | 7.7 | 0.00 | Jun 11, 2026 | Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed. | ||
| CVE-2026-50005 | Hig | 0.50 | 7.7 | 0.00 | Jun 11, 2026 | Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds. | ||
| CVE-2026-84398 | Hig | 0.49 | 7.5 | 0.00 | Sep 18, 2026 | CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration… | ||
| CVE-2026-82578 | Hig | 0.49 | 7.5 | 0.00 | Sep 11, 2026 | When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks. | ||
| CVE-2026-82563 | Hig | 0.49 | 7.6 | 0.00 | Sep 9, 2026 | An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior. |
- risk 0.54cvss 8.3epss 0.00
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.
- risk 0.54cvss 8.3epss 0.00
The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.
- risk 0.54cvss 8.3epss 0.00
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
- risk 0.53cvss —epss 0.00
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials…
- risk 0.53cvss 8.1epss 0.01
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
- risk 0.53cvss 8.2epss 0.00
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
- risk 0.53cvss 8.1epss 0.00
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.
- risk 0.53cvss 8.1epss 0.00
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully…
- risk 0.53cvss 8.1epss 0.01
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
- risk 0.53cvss 8.1epss 0.00
Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any…
- risk 0.53cvss 8.2epss 0.00
The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
- risk 0.52cvss 8.0epss 0.00
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
- risk 0.51cvss 7.8epss 0.00
Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of…
- risk 0.50cvss —epss 0.00
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed…
- risk 0.50cvss 7.7epss 0.00
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
- risk 0.50cvss 7.7epss 0.00
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
- risk 0.49cvss 7.5epss 0.00
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration…
- risk 0.49cvss 7.5epss 0.00
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
- risk 0.49cvss 7.6epss 0.00
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
Page 3 of 7