Sbaresearch
Products
2- 5 CVEs
- 1 CVE
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-41259 | Hig | 0.40 | — | 0.00 | Jun 3, 2026 | SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update. | ||
| CVE-2026-18362 | Med | 0.00 | 5.9 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks. | ||
| CVE-2026-18361 | Hig | 0.00 | 7.6 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function. | ||
| CVE-2026-18360 | Hig | 0.00 | 7.6 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function. | ||
| CVE-2026-16970 | Med | 0.00 | 4.2 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time. | ||
| CVE-2026-16969 | Hig | 0.00 | 7.6 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function. |
- risk 0.40cvss —epss 0.00
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.
- risk 0.00cvss 5.9epss 0.00
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
- risk 0.00cvss 7.6epss 0.00
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
- risk 0.00cvss 7.6epss 0.00
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
- risk 0.00cvss 4.2epss 0.00
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
- risk 0.00cvss 7.6epss 0.00
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.