Known Vulnerabilities for Config by Phoenixcontact
Listed below are 10 of the newest known vulnerabilities associated with "Config" by "Phoenixcontact".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69097 json | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary co... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-67326 json | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers ... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67320 json | axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens m... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67319 json | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the Java... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67316 json | axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has al... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-66724 json | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-65902 json | DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEF... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-65895 json | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowi... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-64644 json | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through ... | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-64642 json | Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests t... | Not Provided | 2026-07-27 | 2026-07-28 |