VYPR

Vendor CVEs

Cisagov

All CVEs

205 total · sorted by risk
  • CVE-2025-53704HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

  • CVE-2024-50054HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.

  • CVE-2023-39452HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

  • CVE-2022-1704HigAug 5, 2022
    risk 0.49cvss 7.6epss 0.01

    Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

  • CVE-2022-1667HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script

  • CVE-2021-38448HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.00

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

  • CVE-2019-10953HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.03

    ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

  • CVE-2021-38455HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

  • CVE-2026-56414HigJun 26, 2026
    risk 0.47cvss 7.2epss 0.00

    A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of…

  • CVE-2026-54479HigJun 25, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to…

  • CVE-2026-6411HigMay 7, 2026
    risk 0.47cvss 7.3epss 0.00

    This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to the presence of a hardcoded AES key within the application, the encrypted data…

  • CVE-2026-90451HigSep 11, 2026
    risk 0.46cvss —epss 0.00

    An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that…

  • CVE-2026-63177HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated…

  • CVE-2025-71412HigAug 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio…

  • CVE-2025-71409HigAug 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

  • CVE-2026-61389HigJul 16, 2026
    risk 0.46cvss 7.0epss 0.00

    An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

  • CVE-2026-60063HigJul 16, 2026
    risk 0.46cvss 7.0epss 0.00

    An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

  • CVE-2026-33560HigJun 26, 2026
    risk 0.46cvss 7.1epss 0.00

    The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable…

  • CVE-2025-55067HigOct 23, 2025
    risk 0.46cvss 7.1epss 0.00

    The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as…

  • CVE-2026-81305MedSep 18, 2026
    risk 0.44cvss 6.8epss 0.00

    CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected…

  • CVE-2026-66372MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

  • CVE-2025-64770MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

  • CVE-2025-62674MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

  • CVE-2026-68953MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

  • CVE-2026-77975MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use…

  • CVE-2026-19671MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream…

  • CVE-2026-63133MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries…

  • CVE-2026-66720MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during …

  • CVE-2026-66369MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,…

  • CVE-2026-66364MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,…

  • CVE-2026-66349MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing…

  • CVE-2026-65421MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

  • CVE-2026-63550MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position …

  • CVE-2026-56758MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.

  • CVE-2026-44622MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-52866MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

  • CVE-2026-50034MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

  • CVE-2026-1495MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.

  • CVE-2025-12636MedNov 6, 2025
    risk 0.42cvss 6.5epss 0.00

    The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of…

  • CVE-2025-30512MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

  • CVE-2024-42495MedSep 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

  • CVE-2021-38396MedOct 4, 2021
    risk 0.42cvss 6.5epss 0.00

    The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.

  • CVE-2026-21404MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful…

  • CVE-2026-35555MedMay 12, 2026
    risk 0.41cvss 6.3epss 0.00

    PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

  • CVE-2025-12357MedOct 31, 2025
    risk 0.41cvss 6.3epss 0.01

    By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable …

  • CVE-2025-27714MedAug 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code execution or system compromise.

  • CVE-2025-24489MedAug 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise.

  • CVE-2023-50703MedDec 20, 2023
    risk 0.41cvss 6.3epss 0.00

    An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.

  • CVE-2026-57896MedJul 16, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could lead to limited information disclosure or disruption of the affected product.

  • CVE-2025-67652MedJan 22, 2026
    risk 0.40cvss 6.1epss 0.00

    An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type…