Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-18116 | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in… | Unknown | 2026-09-14 | Environment Specific |
| CVE-2026-14986 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARG… | Medium (6.8) | 2026-09-14 | Environment Specific |
| CVE-2026-91146 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, … | Medium (6.1) | 2026-09-14 | Environment Specific |
| CVE-2026-91145 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to… | High (7.1) | 2026-09-14 | Environment Specific |
| CVE-2026-91144 | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpo… | High (7.5) | 2026-09-14 | Environment Specific |