-
CVE-2026-22622
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
-
CVE-2026-22622
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
-
CVE-2026-22622
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
-
CVE-2026-22621
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
-
CVE-2026-22621
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
-
CVE-2026-22621
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
-
CVE-2026-22621
•
published on July 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
-
CVE-2026-22620
•
published on July 30, 2026
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
-
CVE-2026-22620
•
published on July 30, 2026
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
-
CVE-2026-22620
•
published on July 30, 2026
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
-
CVE-2026-22620
•
published on July 30, 2026
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
-
CVE-2026-16970
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
-
CVE-2026-16970
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
-
CVE-2026-16970
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
-
CVE-2026-16970
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
-
CVE-2026-18362
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
-
CVE-2026-18362
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
-
CVE-2026-18362
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
-
CVE-2026-18362
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
-
CVE-2026-16971
•
published on July 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.