Vendor CVEs
Cisagov
All CVEs
205 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-25051 | Med | 0.40 | 6.1 | 0.00 | Jan 22, 2026 | An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to network resources for lateral attacks. | ||
| CVE-2026-90448 | Hig | 0.39 | — | 0.00 | Sep 11, 2026 | A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an… | ||
| CVE-2026-90447 | Hig | 0.39 | — | 0.00 | Sep 11, 2026 | A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service… | ||
| CVE-2026-90445 | Hig | 0.39 | — | 0.00 | Sep 11, 2026 | An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries… | ||
| CVE-2026-90457 | Med | 0.38 | — | 0.00 | Sep 11, 2026 | The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a… | ||
| CVE-2026-90449 | Med | 0.38 | — | 0.00 | Sep 11, 2026 | When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative… | ||
| CVE-2026-40425 | Med | 0.37 | 5.7 | 0.00 | May 29, 2026 | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. | ||
| CVE-2026-33570 | Med | 0.37 | 5.7 | 0.00 | May 12, 2026 | PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions. | ||
| CVE-2026-26049 | Med | 0.37 | 5.7 | 0.00 | Feb 20, 2026 | The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observation via shoulder surfing, … | ||
| CVE-2021-42699 | Med | 0.37 | 5.7 | 0.01 | Nov 5, 2021 | The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account. | ||
| CVE-2026-61378 | Med | 0.36 | 5.5 | 0.00 | Jul 16, 2026 | A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash. | ||
| CVE-2026-6807 | Med | 0.36 | 5.5 | 0.00 | Apr 28, 2026 | A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process. | ||
| CVE-2022-2569 | Med | 0.36 | 5.5 | 0.00 | Aug 24, 2022 | The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users | ||
| CVE-2026-19670 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx… | ||
| CVE-2026-63134 | Med | 0.35 | 5.4 | 0.00 | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An… | ||
| CVE-2026-44611 | Med | 0.35 | 5.4 | 0.00 | May 29, 2026 | Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. | ||
| CVE-2026-42951 | Med | 0.35 | 5.4 | 0.00 | May 29, 2026 | An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. | ||
| CVE-2020-14479 | Med | 0.35 | 5.3 | 0.01 | Apr 1, 2022 | Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server | ||
| CVE-2026-90455 | Med | 0.34 | — | 0.00 | Sep 11, 2026 | A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a… | ||
| CVE-2025-71411 | Med | 0.34 | 5.3 | 0.00 | Aug 7, 2026 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency. | ||
| CVE-2026-42932 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2026 | Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can… | ||
| CVE-2026-4293 | Med | 0.34 | 5.3 | 0.00 | May 20, 2026 | The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser. | ||
| CVE-2025-31147 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. | ||
| CVE-2025-25276 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can hijack other users' devices and potentially control them. | ||
| CVE-2025-24850 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An attacker can export other users' plant information. | ||
| CVE-2025-24315 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). | ||
| CVE-2025-31357 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a user's plant list by knowing the username. | ||
| CVE-2025-30514 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). | ||
| CVE-2025-27938 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). | ||
| CVE-2025-35430 | Med | 0.33 | 5.0 | 0.00 | Sep 17, 2025 | CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2. | ||
| CVE-2025-53471 | Med | 0.33 | 5.1 | 0.00 | Jul 11, 2025 | Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. | ||
| CVE-2026-90452 | Med | 0.32 | — | 0.00 | Sep 11, 2026 | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could… | ||
| CVE-2022-2137 | Med | 0.32 | 4.9 | 0.01 | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information | ||
| CVE-2026-81824 | Med | 0.31 | 4.7 | 0.00 | Sep 8, 2026 | The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link. | ||
| CVE-2026-43510 | Med | 0.31 | 5.9 | 0.00 | May 7, 2026 | manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30. | ||
| CVE-2026-50099 | Med | 0.30 | 4.6 | 0.00 | Jun 12, 2026 | During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell… | ||
| CVE-2024-38279 | Med | 0.30 | 4.6 | 0.00 | Jun 13, 2024 | The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes. | ||
| CVE-2025-67634 | Med | 0.29 | 4.4 | 0.00 | Dec 12, 2025 | The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The… | ||
| CVE-2024-53683 | Med | 0.29 | 4.4 | 0.00 | Jan 17, 2025 | A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use. | ||
| CVE-2026-17264 | Med | 0.28 | 4.3 | 0.00 | Aug 7, 2026 | Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2026-90454 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise… | ||
| CVE-2026-90450 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any… | ||
| CVE-2026-90446 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an… | ||
| CVE-2026-90443 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes… | ||
| CVE-2025-35434 | Med | 0.27 | 4.2 | 0.00 | Sep 17, 2025 | CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2. | ||
| CVE-2024-39278 | Med | 0.27 | 4.2 | 0.00 | Sep 5, 2024 | Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data. | ||
| CVE-2023-50706 | Med | 0.27 | 4.1 | 0.00 | Dec 20, 2023 | A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens. | ||
| CVE-2026-90453 | Med | 0.26 | — | 0.00 | Sep 11, 2026 | A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's… | ||
| CVE-2026-85478 | Low | 0.23 | 3.5 | 0.00 | Sep 18, 2026 | A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that… | ||
| CVE-2024-54681 | Low | 0.23 | 3.5 | 0.00 | Jan 17, 2025 | Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application. |
- risk 0.40cvss 6.1epss 0.00
An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to network resources for lateral attacks.
- risk 0.39cvss —epss 0.00
A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an…
- risk 0.39cvss —epss 0.00
A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service…
- risk 0.39cvss —epss 0.00
An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries…
- risk 0.38cvss —epss 0.00
The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a…
- risk 0.38cvss —epss 0.00
When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative…
- risk 0.37cvss 5.7epss 0.00
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
- risk 0.37cvss 5.7epss 0.00
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.
- risk 0.37cvss 5.7epss 0.00
The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observation via shoulder surfing, …
- risk 0.37cvss 5.7epss 0.01
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.
- risk 0.36cvss 5.5epss 0.00
A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process.
- risk 0.36cvss 5.5epss 0.00
The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users
- risk 0.35cvss 5.4epss 0.00
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx…
- risk 0.35cvss 5.4epss 0.00
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An…
- risk 0.35cvss 5.4epss 0.00
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
- risk 0.35cvss 5.4epss 0.00
An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.
- risk 0.35cvss 5.3epss 0.01
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
- risk 0.34cvss —epss 0.00
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a…
- risk 0.34cvss 5.3epss 0.00
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
- risk 0.34cvss 5.3epss 0.00
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can…
- risk 0.34cvss 5.3epss 0.00
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can hijack other users' devices and potentially control them.
- risk 0.34cvss 5.3epss 0.00
An attacker can export other users' plant information.
- risk 0.34cvss 5.3epss 0.01
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a user's plant list by knowing the username.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
- risk 0.33cvss 5.0epss 0.00
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.
- risk 0.33cvss 5.1epss 0.00
Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- risk 0.32cvss —epss 0.00
Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could…
- risk 0.32cvss 4.9epss 0.01
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
- risk 0.31cvss 4.7epss 0.00
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
- risk 0.31cvss 5.9epss 0.00
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
- risk 0.30cvss 4.6epss 0.00
During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell…
- risk 0.30cvss 4.6epss 0.00
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
- risk 0.29cvss 4.4epss 0.00
The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The…
- risk 0.29cvss 4.4epss 0.00
A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.
- risk 0.28cvss 4.3epss 0.00
Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.
- risk 0.27cvss —epss 0.00
A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise…
- risk 0.27cvss —epss 0.00
The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any…
- risk 0.27cvss —epss 0.00
An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an…
- risk 0.27cvss —epss 0.00
A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes…
- risk 0.27cvss 4.2epss 0.00
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.
- risk 0.27cvss 4.2epss 0.00
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
- risk 0.27cvss 4.1epss 0.00
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.
- risk 0.26cvss —epss 0.00
A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's…
- risk 0.23cvss 3.5epss 0.00
A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that…
- risk 0.23cvss 3.5epss 0.00
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.
Page 4 of 5