VYPR

Vendor CVEs

Cisagov

All CVEs

159 total · sorted by risk
  • CVE-2025-64128CriNov 26, 2025
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary…

  • CVE-2025-64127CriNov 26, 2025
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute …

  • CVE-2025-64126CriNov 26, 2025
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker…

  • CVE-2025-58083CriNov 15, 2025
    risk 0.65cvss 10.0epss 0.01

    General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

  • CVE-2025-36535CriMay 21, 2025
    risk 0.65cvss 10.0epss 0.01

    The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.

  • CVE-2023-41084CriSep 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

  • CVE-2020-12030CriSep 29, 2021
    risk 0.65cvss 10.0epss 0.01

    There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

  • CVE-2026-28742CriJun 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence…

  • CVE-2026-7786CriMay 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device…

  • CVE-2026-7251CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.01

    Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the…

  • CVE-2026-25775CriApr 24, 2026
    risk 0.64cvss 9.8epss 0.00

    A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges,…

  • CVE-2025-13926CriApr 9, 2026
    risk 0.64cvss 9.8epss 0.00

    An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.

  • CVE-2026-25715CriFeb 20, 2026
    risk 0.64cvss 9.8epss 0.01

    The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the web management interface and Telnet service. This effectively disables …

  • CVE-2026-1670CriFeb 17, 2026
    risk 0.64cvss 9.8epss 0.01

    The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

  • CVE-2026-24789CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

  • CVE-2025-64130CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

  • CVE-2025-58428CriOct 23, 2025
    risk 0.64cvss 9.9epss 0.01

    The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker…

  • CVE-2025-54807CriSep 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.

  • CVE-2025-2567CriApr 15, 2025
    risk 0.64cvss 9.8epss 0.00

    An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This would result in potential safety hazards in fuel storage and transportation.

  • CVE-2024-47138CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

  • CVE-2023-7244CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code…

  • CVE-2023-7243CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write while analyzing specific Ethercat datagrams. This could allow an attacker to cause arbitrary code execution.

  • CVE-2022-2197CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.01

    By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations.

  • CVE-2022-2103CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.

  • CVE-2021-38477CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.01

    There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.

  • CVE-2026-40702CriJun 25, 2026
    risk 0.61cvss 9.4epss 0.00

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is…

  • CVE-2025-13607CriDec 10, 2025
    risk 0.61cvss 9.4epss 0.01

    A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

  • CVE-2022-2105CriJun 24, 2022
    risk 0.61cvss 9.4epss 0.01

    Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.

  • CVE-2026-5387CriApr 15, 2026
    risk 0.60cvss epss 0.00

    The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters,…

  • CVE-2024-9834CriNov 14, 2024
    risk 0.60cvss 9.3epss 0.00

    Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.

  • CVE-2024-9832CriNov 14, 2024
    risk 0.60cvss 9.3epss 0.00

    There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to device settings that…

  • CVE-2026-5386CriMay 29, 2026
    risk 0.59cvss 9.1epss 0.01

    The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.

  • CVE-2026-8598CriMay 20, 2026
    risk 0.59cvss 9.1epss 0.01

    An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

  • CVE-2026-6284CriApr 17, 2026
    risk 0.59cvss 9.1epss 0.00

    An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

  • CVE-2026-1632CriFeb 3, 2026
    risk 0.59cvss 9.1epss 0.00

    MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

  • CVE-2022-1521CriJun 24, 2022
    risk 0.59cvss 9.1epss 0.01

    LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.

  • CVE-2024-25574HigApr 1, 2024
    risk 0.58cvss 8.8epss 0.09

    SQL injection vulnerability exists in GetDIAE_usListParameters.

  • CVE-2022-40967HigOct 27, 2022
    risk 0.58cvss 8.8epss 0.08

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

  • CVE-2026-55676HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file…

  • CVE-2026-42947HigJun 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker…

  • CVE-2026-5768HigMay 29, 2026
    risk 0.57cvss 8.8epss 0.00

    The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping…

  • CVE-2025-14751HigJan 22, 2026
    risk 0.57cvss epss 0.00

    A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.

  • CVE-2025-12556HigNov 6, 2025
    risk 0.57cvss 8.8epss 0.00

    An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.

  • CVE-2024-43099HigSep 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can…

  • CVE-2024-28029HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

  • CVE-2026-9039HigMay 28, 2026
    risk 0.56cvss epss 0.00

    A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and…

  • CVE-2026-9038HigMay 28, 2026
    risk 0.56cvss epss 0.00

    A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory…

  • CVE-2026-4436HigApr 9, 2026
    risk 0.56cvss 8.6epss 0.00

    A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

  • CVE-2025-47698HigSep 18, 2025
    risk 0.56cvss epss 0.00

    An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.

  • CVE-2026-6824HigMay 29, 2026
    risk 0.55cvss 8.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend.…

Page 1 of 4