CVEs we hold for Mz
Records whose assigning authority named Mz as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-65056mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filteringmzxrai mcp-webresearch
CVE-2026-50103Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850MZ Automation libIEC61850
CVE-2026-19259MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based…MZ Automation libiec61850
CVE-2026-19206MZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadless heap-based overflowMZ Automation libiec61850
CVE-2026-19108MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after freeMZ Automation libiec61850
CVE-2026-18583mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-boundsmz-automation libiec61850
CVE-2026-18582mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heapmz-automation libiec61850
CVE-2022-3976MZ Automation libiec61850 MMS File Services mms_client_files.c path traversalMZ Automation libiec61850
CVE-2022-2971MZ Automation libIEC61850 Access of Resource Using Incompatible Type ('Type Confusion')MZ Automation libIEC61850
CVE-2022-1302Malformed Goose Message in LibIEC61850 may result in a denial of serviceMZ Automation libIEC61850
31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.