vciy

CVEs we hold for Mb

Records whose assigning authority named Mb as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8494Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Titlembis Permalink Manager Lite
CVE-2026-41445KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()mborgerding kissfft
CVE-2026-40852Command injection via malicious configurationMB connect line mbNET.mini; Helmholz REX200/250…
CVE-2026-40851Command injection via USBMB connect line mbNET.mini; Helmholz REX200/250…
CVE-2026-40850Unauthenticated SQLi in getAccountData functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40849Authenticated SQLi in user_alarmprofile viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40848Authenticated SQLi in tag viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40847Authenticated SQLi in system_tag viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40846Authenticated SQLi in system viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40845Authenticated SQLi in devices_configuration viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40844Authenticated SQLi in dashboard viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40843Authenticated SQLi in alarming viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40842Authenticated SQLi in getWidgetTags functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40841Authenticated SQLi in getProjectTags functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40840Authenticated SQLi in VerifyCreateLicences functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40839Authenticated SQLi in getComponentScalings functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40838Authenticated SQLi in getDeviceScalings functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40837Authenticated SQLi in getProjectScalings functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40836Authenticated SQLi in inmessage modelMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40835Authenticated SQLi in saveObjectFromData functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40834Authenticated SQLi in saveDashboardLayout functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40833Authenticated SQLi in saveDashboardLayout functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40832Authenticated SQLi in getDevicegroups functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40831Authenticated SQLi in Easy ViewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40830Authenticated SQLi in UpdateParam functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40829Authenticated SQLi in UpdateParam functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40828Authenticated SQLi in DeleteSysLogEntry functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40827Authenticated SQLi in _RemoveRequest functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40826Authenticated SQLi in dsgvo_contracts viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40825Authenticated SQLi in accountstatus viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40824Authenticated SQLi in accountstatus viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40823Authenticated SQLi in DevSerialReset functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40822Authenticated SQLi in DevSerialReset functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40821Authenticated SQLi in getAccountByID functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40819Unauthenticated SQLi in sync_data24 taskMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40818Unauthenticated SQLi in _mb24confi_getDevice function functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40817Unauthenticated SQLi in getAlarmProfiles functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40816Unauthenticated SQLi in _mb24confi_getTagAlarm functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40815Unauthenticated SQLi in _mb24api_getUserAccount functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40814Unauthenticated SQLi in _mb24confi_getTagAlarm functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40813Unauthenticated SQLi in getLiveValuesMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40812Unauthenticated SQLi in getLiveValues functionMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40811Unauthenticated SQLi in ssoabstractserviceMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-40810Unauthenticated SQLi in userinfo EndpointMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-35085Stack buffer overflow in method gdv-serverconfigMBS Triple-X PROFINET+M-Bus
CVE-2026-35084Stack buffer overflow in method dali-devconfigMBS Triple-X PROFINET+M-Bus
CVE-2026-35083Stack buffer overflow in method bac-deviceobjectMBS Triple-X PROFINET+M-Bus
CVE-2026-35082Local file inclusion vulnerability and deletion in ugw-logread methodMBS Triple-X PROFINET+M-Bus
CVE-2026-35081Arbitrary process termination vulnerability in method ugw-logstopMBS Triple-X PROFINET+M-Bus
CVE-2026-35080Arbitrary file delete vulnerability in method ugw-restoreinfoMBS Triple-X PROFINET+M-Bus
CVE-2026-35079Arbitrary file delete vulnerability in method ugw-restoreMBS Triple-X PROFINET+M-Bus
CVE-2026-35078Arbitrary file delete vulnerability in method ugw-logstopMBS Triple-X PROFINET+M-Bus
CVE-2026-35077Arbitrary file delete vulnerability in method ugw-delete-fileMBS Triple-X PROFINET+M-Bus
CVE-2026-35076Arbitrary file delete vulnerability in method bac-scanresultMBS Triple-X PROFINET+M-Bus
CVE-2026-35075Hardcoded default Password for Service AccountMBS Triple-X PROFINET+M-Bus
CVE-2026-33617MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 EndpointMB connect line mymbCONNECT24
CVE-2026-33616MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api EndpointMB connect line mymbCONNECT24
CVE-2026-33615MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo EndpointMB connect line mymbCONNECT24
CVE-2026-33614MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpointMB connect line mymbCONNECT24
CVE-2026-33613MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArrayMB connect line mymbCONNECT24
CVE-2026-32969Pre-Auth Blind SQLi in userinfo EndpointMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-32968Unauthenticated RCE in com_mb24sysapiMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-14448Authenticated RCE in system_certificates viewMB connect line mymbCONNECT24; Helmholz myREX24V2…
CVE-2026-10521Authenticated unintended access to critical program parametersMB connect line mymbCONNECT24
CVE-2025-52570Letmein connection limiter allows an arbitrary amount of simultaneous connectionsmbuesch letmein
CVE-2025-52497no title heldMbed mbedtls
CVE-2025-52496no title heldMbed mbedtls
CVE-2025-49601no title heldMbed mbedtls
CVE-2025-49600no title heldMbed mbedtls
CVE-2025-49087no title heldMbed mbedtls
CVE-2025-48965no title heldMbed mbedtls
CVE-2025-47917no title heldMbed mbedtls
CVE-2025-41772wwwupdate.cgi Session token in URLMBS UBR-LON
CVE-2025-41767Signature bypass on update uploadMBS UBR-LON
CVE-2025-41766Stack buffer overflow on parsing web requestMBS UBR-LON
CVE-2025-41765Unchecked role in wwwupload.cgiMBS UBR-LON
CVE-2025-41764Unchecked role in wwwupdate.cgiMBS UBR-LON
CVE-2025-41763Unchecked role in wwwdnload.cgiMBS UBR-LON
CVE-2025-41762Secret leak with wwwdnload.cgiMBS UBR-LON
CVE-2025-41761Privilege escalation possibleMBS UBR-LON
CVE-2025-41760Pass filter with Empty TableMBS UBR-LON
CVE-2025-41759Use of wildcard (“*” or “all”) in Block listMBS UBR-LON
CVE-2025-41758Arbitrary Write with wwwupload.cgiMBS UBR-LON
CVE-2025-41757Arbitrary Write with ubr-restoreMBS UBR-LON
CVE-2025-41756Arbitrary Write with ubr-editfileMBS UBR-LON
CVE-2025-41755Arbitrary Read with ubr-logreadMBS UBR-LON
CVE-2025-41754Arbitrary Read with ubr-editfileMBS UBR-LON
CVE-2025-41688High Privilege RCE via LUA Sandbox EscapeMB connect line mbNET/mbNET.rokey; Helmholz REX 300…
CVE-2025-41681Persistent Cross-Site Scripting via POST Requests Due to Improper Neutralization of InputMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41679Unauthenticated Buffer Overflow in Conftool Service Leading to Denial of ServiceMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41678SQL Injection via POST Requests Allowing Configuration Database ManipulationMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41677Resource Exhaustion via POST Requests to send-mail ActionMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41676Resource Exhaustion via POST Requests to send-sms ActionMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41675Remote Command Injection via GET in Cloud Server Communication Script Due to Improper Input NeutralizationMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41674Remote Command Injection in diagnostic Action Due to Improper Input NeutralizationMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-41673Remote Command Injection in send_sms Action Due to Improper Input NeutralizationMB connect line mbNET.mini; Helmholz REX 100
CVE-2025-34297KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_allocmborgerding/kissfft
CVE-2025-3091MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24MB connect line mymbCONNECT24; Helmholz myREX24…
CVE-2025-3090MB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24MB connect line mymbCONNECT24; Helmholz myREX24…
CVE-2025-27810no title heldMbed mbedtls
CVE-2025-27809no title heldMbed mbedtls
CVE-2025-23563WordPress Explore pages plugin <= 1.01 - Reflected Cross Site Scripting (XSS) vulnerabilitymbyte Explore pages
CVE-2024-8195Permalink Manager Lite <= 2.4.4 - Missing Authorization to Unauthenticated Sensitive Information Exposurembis Permalink Manager Lite
CVE-2024-45276MB connect line/Helmholz: tmp directory exposed via webserviceMB connect line mbNET.mini; Helmholz REX100
CVE-2024-45275MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwordsMB connect line mbNET.mini; Helmholz REX100
CVE-2024-45274MB connect line/Helmholz: Remote code execution via confnet serviceMB connect line mbNET.mini; Helmholz REX100
CVE-2024-45273MB connect line/Helmholz: Weak encryption of configuration fileMB connect line mymbCONNECT24; Helmholz REX100…
CVE-2024-45272MB connect line/Helmholz: Generation of weak passwords vulnerabilityMB connect line mymbCONNECT24; Helmholz myREX24 V2…
CVE-2024-45271MB connect line/Helmholz: Remote code execution due to improper input validationMB connect line mbNET.mini; Helmholz REX100
CVE-2024-38742WordPress MBE eShip plugin <= 2.1.2 - Sensitive Data Exposure vulnerabilityMBE eShip
CVE-2024-38729WordPress MBE eShip plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) vulnerabilitymbeelink MBE eShip
CVE-2024-37953WordPress MBE eShip plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerabilityMBE eShip
CVE-2024-2738Permalink Manager Lite and Permalink Manager Pro <= 2.4.3.1 - Reflected Cross-Site Scriptingmbis Permalink Manager Pro
CVE-2024-2543Plugin Permalink <= 2.4.3.1 - Missing Authorization via get_uri_editormbis Permalink Manager Lite
CVE-2024-2538Permalink Manager <= 2.4.3.1 - Missing Authorization to Authenticated(Author+) Arbitrary Post Slug Modificationmbis Permalink Manager Lite
CVE-2024-23943MB connect line: Cloud API access due to a lack of authentication for a critical functionMB connect line mymbCONNECT24
CVE-2024-23942MB connect line: Configuration File on the client workstation is not encryptedMB connect line mymbCONNECT24
CVE-2024-1163Path traversal vulnerability in mapshapermbloch/mapshaper
CVE-2024-10143MB Custom Post Types & Custom Taxonomies < 2.7.7 - Admin+ Stored XSSUnknown MB Custom Post Types & Custom Taxonomies
CVE-2023-25965WordPress Upload Resume plugin <= 1.2.0 - Sensitive Data Exposure vulnerabilitymbbhatti Upload Resume
CVE-2023-1779Helmholz and MB Connect Line: Account takeover via password reset in multiple productsMB Connect Line mymbCONNECT24; Helmholz myREX24…
CVE-2023-0985Helmholz and MB Connect Line: Account takeover via password reset in multiple productsMB Connect Line mymbCONNECT24; Helmholz myREX24…
CVE-2022-4410Permalink Manager Lite <= 2.2.20.3 - Authenticated Stored Cross-Site Scriptingmbis Permalink Manager Lite
CVE-2022-4021Permalink Manager Lite <= 2.2.20.1 - Cross-Site Request Forgerymbis Permalink Manager Lite
CVE-2022-2435AnyMind Widget <= 1.1 - Cross-Site Request Forgery to Cross-Site Scriptingmbeltwski AnyMind Widget
CVE-2022-23535LiteDB contains Deserialization of Untrusted Datambdavid LiteDB
CVE-2022-22520User enumeration vulnerability in MB connect line and Helmholz productsMB connect line mbCONNECT24; Helmholz myREX24…
CVE-2021-34580Remote user enumeration in mymbCONNECT24, mbCONNECT24 <= 2.9.0MB connect line mbCONNECT24
CVE-2021-34575Information Exposure in mymbCONNECT24, mbCONNECT24 <= 2.8.0MB connect line mbCONNECT24
CVE-2021-34574Password policy evasion in products of MB connect line and HelmholzMB connect line mbCONNECT24; Helmholz myREX24…
CVE-2021-33527OS Command Injection in mbDIALUP <= 3.9R0.0MB connect line mbDIALUP
CVE-2021-33526Privilege escalation in mbDIALUP <= 3.9R0.0MB connect line mbDIALUP
CVE-2020-12530no title heldMB connect line mbCONNECT24
CVE-2020-12529no title heldMB connect line mbCONNECT24
CVE-2020-12528no title heldMB connect line mbCONNECT24
CVE-2020-12527Improper Access Validation in products of MB connect line and HelmholzMB connect line mbCONNECT24; Helmholz myREX24…
CVE-2016-15032mback2k mh_httpbl Extension class.tx_mhhttpbl.php stopOutput cross site scriptingmback2k mh_httpbl Extension
CVE-2015-10106mback2k mh_httpbl Extension index.php moduleContent sql injectionmback2k mh_httpbl Extension

138 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.