Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97871 1 Zhonglun 1 Cloudpos 2026-09-25 7.3 High
A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-97866 1 Zhonglun 1 Cloudpos 2026-09-25 5.6 Medium
A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic Update. Executing a manipulation of the argument version/url/packagekey/package name can lead to channel accessible by non-endpoint. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.