Vendor CVEs
SICK AG
All CVEs
156 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-22919 | Low | 0.25 | 3.8 | 0.00 | Jan 15, 2026 | An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data. | ||
| CVE-2025-58578 | Low | 0.25 | 3.8 | 0.00 | Oct 6, 2025 | A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation. | ||
| CVE-2025-32471 | Low | 0.24 | 3.7 | 0.00 | Apr 28, 2025 | The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks. | ||
| CVE-2025-49198 | Low | 0.20 | 3.1 | 0.00 | Jun 12, 2025 | The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens. | ||
| CVE-2025-58589 | Low | 0.18 | 2.7 | 0.00 | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. | ||
| CVE-2026-22920 | 0.00 | — | 0.00 | Jan 15, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
- risk 0.25cvss 3.8epss 0.00
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
- risk 0.25cvss 3.8epss 0.00
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
- risk 0.24cvss 3.7epss 0.00
The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.
- risk 0.20cvss 3.1epss 0.00
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
- risk 0.18cvss 2.7epss 0.00
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.
- CVE-2026-22920Jan 15, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Page 4 of 4