Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

On Prem Enterprise Server CRITICAL 9.8
CVE-2026-11414

A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro…

Fix: 8.1.1+
Fix from $2,300 2026-06-05
On Prem Enterprise Server CRITICAL 9.8
CVE-2026-11420

Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to…

Fix: 8.1.1+
Fix from $2,300 2026-06-05
On Prem Enterprise Server HIGH 8.8
CVE-2026-11419

A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled …

Fix: 8.1.1+
Fix from $1,950 2026-06-05
On Prem Enterprise Server HIGH 7.6
CVE-2025-27380

HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary Java…

Fix: 7.0.6+
Fix from $1,950 2026-01-22
On Prem Enterprise Server CRITICAL 9.8
CVE-2025-27378

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this …

Fix: 7.0.6+
Fix from $2,300 2026-01-22
Designer MEDIUM 5.3
CVE-2025-27377

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-th…

Fix: 25.2.0+
Fix from $1,600 2026-01-22
Altium Live MEDIUM 6.1
CVE-2026-1011

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitizati…

Fix: after 1.1.1.39
Fix from $1,600 2026-01-16
Altium Live MEDIUM 5.4
CVE-2026-1009

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An …

Mitigation only
Fix from $1,600 2026-01-15
On Prem Enterprise Server MEDIUM 5.4
CVE-2026-1010

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form…

Mitigation only
Fix from $1,600 2026-01-15
Altium Live MEDIUM 5.4
CVE-2026-1008

A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization a…

Mitigation only
Fix from $1,600 2026-01-15