VYPR

Vendor CVEs

SICK AG

All CVEs

156 total · sorted by risk
  • CVE-2026-22919LowJan 15, 2026
    risk 0.25cvss 3.8epss 0.00

    An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.

  • CVE-2025-58578LowOct 6, 2025
    risk 0.25cvss 3.8epss 0.00

    A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.

  • CVE-2025-32471LowApr 28, 2025
    risk 0.24cvss 3.7epss 0.00

    The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.

  • CVE-2025-49198LowJun 12, 2025
    risk 0.20cvss 3.1epss 0.00

    The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.

  • CVE-2025-58589LowOct 6, 2025
    risk 0.18cvss 2.7epss 0.00

    When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.

  • CVE-2026-22920Jan 15, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Page 4 of 4