24h | 7d | 30d

Overview

  • MB connect line
  • mbCONNECT24

02 Apr 2026
Published
02 Apr 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.15%

KEV

Description

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

VDE-2026-043
Helmholz: Multiple Vulnerabilities in myREX24V2/myREX24V2.virtual

Multiple vulnerabilities have been discovered in Helmholz myREX24V2/myREX24V2.virtual that could allow RCE, SQLi or information leakage.
CVE-2026-33615, CVE-2026-33616, CVE-2026-33614, CVE-2026-33613, CVE-2026-33617

certvde.com/en/advisories/vde-

helmholz.csaf-tp.certvde.com/.

  • 1
  • 1
  • 0
  • 3h ago

Overview

  • MB connect line
  • mbCONNECT24

02 Apr 2026
Published
02 Apr 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.06%

KEV

Description

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

VDE-2026-043
Helmholz: Multiple Vulnerabilities in myREX24V2/myREX24V2.virtual

Multiple vulnerabilities have been discovered in Helmholz myREX24V2/myREX24V2.virtual that could allow RCE, SQLi or information leakage.
CVE-2026-33615, CVE-2026-33616, CVE-2026-33614, CVE-2026-33613, CVE-2026-33617

certvde.com/en/advisories/vde-

helmholz.csaf-tp.certvde.com/.

  • 1
  • 1
  • 0
  • 3h ago

Overview

  • MB connect line
  • mbCONNECT24

02 Apr 2026
Published
02 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.10%

KEV

Description

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

VDE-2026-043
Helmholz: Multiple Vulnerabilities in myREX24V2/myREX24V2.virtual

Multiple vulnerabilities have been discovered in Helmholz myREX24V2/myREX24V2.virtual that could allow RCE, SQLi or information leakage.
CVE-2026-33615, CVE-2026-33616, CVE-2026-33614, CVE-2026-33613, CVE-2026-33617

certvde.com/en/advisories/vde-

helmholz.csaf-tp.certvde.com/.

  • 1
  • 1
  • 0
  • 3h ago

Overview

  • MB connect line
  • mbCONNECT24

02 Apr 2026
Published
03 Apr 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.04%

KEV

Description

An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

VDE-2026-043
Helmholz: Multiple Vulnerabilities in myREX24V2/myREX24V2.virtual

Multiple vulnerabilities have been discovered in Helmholz myREX24V2/myREX24V2.virtual that could allow RCE, SQLi or information leakage.
CVE-2026-33615, CVE-2026-33616, CVE-2026-33614, CVE-2026-33613, CVE-2026-33617

certvde.com/en/advisories/vde-

helmholz.csaf-tp.certvde.com/.

  • 1
  • 1
  • 0
  • 3h ago

Overview

  • MB connect line
  • mbCONNECT24

02 Apr 2026
Published
02 Apr 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.06%

KEV

Description

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

VDE-2026-043
Helmholz: Multiple Vulnerabilities in myREX24V2/myREX24V2.virtual

Multiple vulnerabilities have been discovered in Helmholz myREX24V2/myREX24V2.virtual that could allow RCE, SQLi or information leakage.
CVE-2026-33615, CVE-2026-33616, CVE-2026-33614, CVE-2026-33613, CVE-2026-33617

certvde.com/en/advisories/vde-

helmholz.csaf-tp.certvde.com/.

  • 1
  • 1
  • 0
  • 3h ago
Showing 31 to 35 of 35 CVEs