VYPR

Vendor CVEs

Cisagov

All CVEs

159 total · sorted by risk
  • CVE-2025-49850HigJun 17, 2025
    risk 0.55cvss epss 0.00

    A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end…

  • CVE-2024-38282HigJun 13, 2024
    risk 0.55cvss epss 0.00

    Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requiring a physical reboot of the system.

  • CVE-2026-42941HigMay 29, 2026
    risk 0.54cvss 8.3epss 0.00

    The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

  • CVE-2026-42929HigMay 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

  • CVE-2026-18164HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.

  • CVE-2026-18844HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully…

  • CVE-2026-49035HigJul 23, 2026
    risk 0.53cvss 8.1epss 0.00

    The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.

  • CVE-2026-31928HigJun 26, 2026
    risk 0.53cvss 8.1epss 0.00

    The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.

  • CVE-2026-50101HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any…

  • CVE-2026-24790HigFeb 20, 2026
    risk 0.53cvss 8.2epss 0.00

    The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.

  • CVE-2024-25567HigMar 21, 2024
    risk 0.53cvss 8.1epss 0.01

    Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.

  • CVE-2023-7242HigMar 1, 2024
    risk 0.53cvss 8.2epss 0.00

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds read during the process of analyzing a specific Ethercat packet. This could allow an attacker to crash the Zeek process and leak…

  • CVE-2021-42536HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

  • CVE-2025-12659HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.

  • CVE-2025-49848HigJun 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of…

  • CVE-2026-50245HigJun 11, 2026
    risk 0.50cvss 7.7epss 0.00

    Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.

  • CVE-2026-50005HigJun 11, 2026
    risk 0.50cvss 7.7epss 0.00

    Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

  • CVE-2026-66360HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap…

  • CVE-2026-44383HigJul 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

  • CVE-2026-42952HigJul 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

  • CVE-2026-50176HigJun 25, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

  • CVE-2026-50108HigJun 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary…

  • CVE-2026-25113HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-26048HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized…

  • CVE-2026-24455HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.

  • CVE-2025-3232HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

  • CVE-2025-53704HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

  • CVE-2024-50054HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.

  • CVE-2023-39452HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

  • CVE-2022-1704HigAug 5, 2022
    risk 0.49cvss 7.6epss 0.01

    Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

  • CVE-2022-1667HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script

  • CVE-2021-38448HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.00

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

  • CVE-2019-10953HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.03

    ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

  • CVE-2021-38455HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

  • CVE-2026-56414HigJun 26, 2026
    risk 0.47cvss 7.2epss 0.00

    A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of…

  • CVE-2026-54479HigJun 25, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to…

  • CVE-2026-6411HigMay 7, 2026
    risk 0.47cvss 7.3epss 0.00

    This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to the presence of a hardcoded AES key within the application, the encrypted data…

  • CVE-2026-63177HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated…

  • CVE-2025-71409HigAug 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

  • CVE-2026-61389HigJul 16, 2026
    risk 0.46cvss 7.0epss 0.00

    An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

  • CVE-2026-60063HigJul 16, 2026
    risk 0.46cvss 7.0epss 0.00

    An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

  • CVE-2026-33560HigJun 26, 2026
    risk 0.46cvss 7.1epss 0.00

    The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable…

  • CVE-2025-55067HigOct 23, 2025
    risk 0.46cvss 7.1epss 0.00

    The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as…

  • CVE-2025-64770MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

  • CVE-2025-62674MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

  • CVE-2026-63133MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries…

  • CVE-2026-66720MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during …

  • CVE-2026-66369MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,…

  • CVE-2026-66364MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,…

  • CVE-2026-66349MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing…