CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sangoma
1Freepbx
Oct 9, 2026
Aug 13, 2026
8.6 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/adm...Show more
FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.Show less
1Sangoma
1Freepbx
Oct 9, 2026
Aug 13, 2026
7.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music....Show more
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels, or create Asterisk call files because applicationUsesDisallowedPlayerOption() does not reject those arguments, resulting in arbitrary command execution as the asterisk service user. This issue is fixed in version 17.0.7.Show less
1Sangoma
1Freepbx
Oct 9, 2026
Aug 13, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnot...Show more
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.Show less
1Sangoma
1Freepbx
Oct 9, 2026
Aug 13, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. A...Show more
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path patched by node/lib/asterisk-manager-patch.js, allowing arbitrary commands to execute as the asterisk service user. This issue is fixed in version 17.0.9.Show less
-
-
Oct 9, 2026
Oct 9, 2026
N/A· v4
N/A· v3
N/A· v2
Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials.
-
-
Oct 9, 2026
Oct 9, 2026
N/A· v4
N/A· v3
N/A· v2
OpENer v2.3/ commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remtoe attacker to cause a denial of service
-
-
Oct 9, 2026
Oct 9, 2026
N/A· v4
N/A· v3
N/A· v2
OpENer v2.3/commit 76b95cf, contains an integer underflow in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service
-
-
Oct 9, 2026
Oct 9, 2026
N/A· v4
N/A· v3
N/A· v2
OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.
-
-
Oct 9, 2026
Oct 9, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride an...Show more
pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.Show less
-
-
Oct 9, 2026
Oct 9, 2026
N/A· v4
4.0 MEDIUM· v3
N/A· v2
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-onl...Show more
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.Show less
-
-
Oct 9, 2026
Oct 8, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array alloc...Show more
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.Show less
-
-
Oct 9, 2026
Oct 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass...Show more
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.Show less
1Microsoft
1Office
Oct 9, 2026
Aug 15, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
1Microsoft
1Office
Oct 9, 2026
Aug 15, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted template, aka "Microsoft Office Remote Code Execution Vulnerability."
2Intel
Oracle
2Fujitsu M10 Firmware
Intelligent Platform Management Interface
Oct 9, 2026
Jul 8, 2013
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the...Show more
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.Show less
1Symantec Veritas
1Backup Exec
Oct 9, 2026
Oct 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
1Linksys
3Befn2ps4
Befsr41Befsr81
Oct 9, 2026
Mar 25, 2002
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string...Show more
Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.Show less
1Denicomp
1Winsock Rshd Nt
Oct 9, 2026
Dec 8, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which c...Show more
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.Show less
1Microsoft
1Windows Nt
Oct 9, 2026
Aug 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.
1Sco
1Openserver
Oct 9, 2026
Feb 8, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.
1Osicom
1Routermate
Oct 9, 2026
Sep 1, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.
-
-
Oct 9, 2026
Aug 1, 1998
N/A· v4
N/A· v3
7.5 HIGH· v2
An SNMP community name is guessable.
2Network Appliance
Snmp
2Netcache
Snmp
Oct 9, 2026
Apr 7, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.
6Bsdi
IbmIsc+3 more
12Aix
Asl Ux 4800Bind+9 more
Oct 9, 2026
Aug 13, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
DNS cache poisoning via BIND, by predictable query IDs.
13Apple
CanonicalDebian+10 more
21Bind
Clustered Data OntapDebian Linux+18 more
Oct 9, 2026
Jul 29, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.