Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-11414 A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-11420 Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 HIGH 8.8 CVE-2026-11419 A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled … On Prem Enterprise Server 8.1.1+ Fix from $1,9502026-06-05 HIGH 7.6 CVE-2025-27380 HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary Java… On Prem Enterprise Server 7.0.6+ Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2025-27378 AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this … On Prem Enterprise Server 7.0.6+ Fix from $2,3002026-01-22 MEDIUM 5.3 CVE-2025-27377 Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-th… Designer 25.2.0+ Fix from $1,6002026-01-22 MEDIUM 6.1 CVE-2026-1011 A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitizati… Altium Live after 1.1.1.39 Fix from $1,6002026-01-16 MEDIUM 5.4 CVE-2026-1009 A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An … Altium Live Mitigation only Fix from $1,6002026-01-15 MEDIUM 5.4 CVE-2026-1010 A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form… On Prem Enterprise Server Mitigation only Fix from $1,6002026-01-15 MEDIUM 5.4 CVE-2026-1008 A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization a… Altium Live Mitigation only Fix from $1,6002026-01-15