CVE Find is a real-time vulnerability database indexing 349 620 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1877 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-6001 |
2026-05-12 10h16 +00:00 |
Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS a... Authorization problems |
8.8 |
High |
|
CVE-2026-41551 |
2026-05-12 10h16 +00:00 |
A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a pat... |
9.1 |
Critical |
|
CVE-2026-25787 |
2026-05-12 10h16 +00:00 |
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "... Cross-site Scripting |
9.1 |
Critical |
|
CVE-2026-25786 |
2026-05-12 10h16 +00:00 |
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communicati... Cross-site Scripting |
9.1 |
Critical |
|
CVE-2026-22924 |
2026-05-12 10h16 +00:00 |
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected applicati... Authorization problems |
9.1 |
Critical |
|
CVE-2025-6577 |
2026-05-12 10h16 +00:00 |
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i... SQL Injection |
9.8 |
Critical |
|
CVE-2025-40949 |
2026-05-12 10h16 +00:00 |
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX ... OS Command Injection |
9.1 |
Critical |
|
CVE-2025-40946 |
2026-05-12 10h16 +00:00 |
A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2... |
8.3 |
High |
|
CVE-2026-39432 |
2026-05-12 09h16 +00:00 |
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured A... Authorization problems |
8.2 |
High |
|
CVE-2026-35227 |
2026-05-12 07h14 +00:00 |
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus T... |
8.2 |
High |