CVE-2026-63280
Published Jul 22, 2026Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
- evidence mentions
- 1
- Buzz score
- 11.9
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
3,283 results · Sorted by Highest Buzz score first
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
Stored condition values could also execute HTML/JavaScript in administrator summaries.
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execut…
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable locatio…
IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks co…
Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform datab…
Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF a…
Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could conseque…
Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who la…
User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restric…
Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visi…
Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP…
IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped…
Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could r…
Administrator URL purges did not consistently require a valid token and cache-management permission.
Custom purge and log paths could escape the site webroot directory.
Custom query URLs could access internal or reserved network services.
CDN credentials were exposed in administrator request URLs.
GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via th…
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.