VYPR

Vendor CVEs

Cisagov

All CVEs

159 total · sorted by risk
  • CVE-2026-65421MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

  • CVE-2026-63550MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position …

  • CVE-2026-56758MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.

  • CVE-2026-44622MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-52866MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

  • CVE-2026-50034MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

  • CVE-2026-1495MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.

  • CVE-2025-12636MedNov 6, 2025
    risk 0.42cvss 6.5epss 0.00

    The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of…

  • CVE-2025-30512MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

  • CVE-2024-42495MedSep 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

  • CVE-2021-38396MedOct 4, 2021
    risk 0.42cvss 6.5epss 0.00

    The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.

  • CVE-2026-21404MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful…

  • CVE-2026-35555MedMay 12, 2026
    risk 0.41cvss 6.3epss 0.00

    PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

  • CVE-2025-12357MedOct 31, 2025
    risk 0.41cvss 6.3epss 0.00

    By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable …

  • CVE-2025-27714MedAug 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code execution or system compromise.

  • CVE-2025-24489MedAug 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise.

  • CVE-2023-50703MedDec 20, 2023
    risk 0.41cvss 6.3epss 0.00

    An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.

  • CVE-2026-57896MedJul 16, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could lead to limited information disclosure or disruption of the affected product.

  • CVE-2025-67652MedJan 22, 2026
    risk 0.40cvss 6.1epss 0.00

    An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type…

  • CVE-2025-25051MedJan 22, 2026
    risk 0.40cvss 6.1epss 0.00

    An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to network resources for lateral attacks.

  • CVE-2026-40425MedMay 29, 2026
    risk 0.37cvss 5.7epss 0.00

    The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

  • CVE-2026-33570MedMay 12, 2026
    risk 0.37cvss 5.7epss 0.00

    PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.

  • CVE-2026-26049MedFeb 20, 2026
    risk 0.37cvss 5.7epss 0.00

    The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observation via shoulder surfing, …

  • CVE-2021-42699MedNov 5, 2021
    risk 0.37cvss 5.7epss 0.00

    The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.

  • CVE-2026-61378MedJul 16, 2026
    risk 0.36cvss 5.5epss 0.00

    A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.

  • CVE-2026-6807MedApr 28, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process.

  • CVE-2022-2569MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

  • CVE-2026-63134MedAug 11, 2026
    risk 0.35cvss 5.4epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An…

  • CVE-2026-44611MedMay 29, 2026
    risk 0.35cvss 5.4epss 0.00

    Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

  • CVE-2026-42951MedMay 29, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

  • CVE-2020-14479MedApr 1, 2022
    risk 0.35cvss 5.3epss 0.01

    Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server

  • CVE-2025-71411MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

  • CVE-2026-42932MedJun 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can…

  • CVE-2026-4293MedMay 20, 2026
    risk 0.34cvss 5.3epss 0.00

    The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.

  • CVE-2025-31147MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

  • CVE-2025-25276MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can hijack other users' devices and potentially control them.

  • CVE-2025-24850MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An attacker can export other users' plant information.

  • CVE-2025-24315MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

  • CVE-2025-31357MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain a user's plant list by knowing the username.

  • CVE-2025-30514MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

  • CVE-2025-27938MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

  • CVE-2025-35430MedSep 17, 2025
    risk 0.33cvss 5.0epss 0.00

    CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.

  • CVE-2025-53471MedJul 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CVE-2022-2137MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • CVE-2026-43510MedMay 7, 2026
    risk 0.31cvss 5.9epss 0.00

    manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.

  • CVE-2026-50099MedJun 12, 2026
    risk 0.30cvss 4.6epss 0.00

    During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell…

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2025-67634MedDec 12, 2025
    risk 0.29cvss 4.4epss 0.00

    The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The…

  • CVE-2024-53683MedJan 17, 2025
    risk 0.29cvss 4.4epss 0.00

    A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.

  • CVE-2026-17264MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.