Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-11414
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro…
On Prem Enterprise Server
8.1.1+
CRITICAL 9.8
CVE-2026-11420
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to…
On Prem Enterprise Server
8.1.1+
HIGH 8.8
CVE-2026-11419
A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled …
On Prem Enterprise Server
8.1.1+
HIGH 7.6
CVE-2025-27380
HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary Java…
On Prem Enterprise Server
7.0.6+
CRITICAL 9.8
CVE-2025-27378
AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this …
On Prem Enterprise Server
7.0.6+
MEDIUM 5.3
CVE-2025-27377
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-th…
Designer
25.2.0+
MEDIUM 6.1
CVE-2026-1011
A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitizati…
Altium Live
after 1.1.1.39
MEDIUM 5.4
CVE-2026-1009
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An …
Altium Live
Mitigation only
MEDIUM 5.4
CVE-2026-1010
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form…
On Prem Enterprise Server
Mitigation only
MEDIUM 5.4
CVE-2026-1008
A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization a…
Altium Live
Mitigation only