Vulnerability index

Browse CVEs

89 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

R Seenet MEDIUM 6.5
CVE-2021-21925

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This c…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21926

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This c…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21927

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This c…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21928

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_filter’ parameter to trigger thi…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21929

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger th…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21930

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21931

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger th…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21932

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ paramet…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21933

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘esn_filter’ paramete…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21934

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ paramet…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21935

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_a…

No fix yet
Fix from $1,600 2021-12-22
R Seenet HIGH 7.8
CVE-2021-21910

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s…

No fix yet
Fix from $1,950 2021-12-22
R Seenet CRITICAL 9.8
CVE-2021-21805EPSS 70%

An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HT…

No fix yet
Fix from $2,300 2021-08-05
R Seenet CRITICAL 9.8
CVE-2021-21804

A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…

No fix yet
Fix from $2,300 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21799EPSS 12%

Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits …

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21800EPSS 14%

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a s…

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21801EPSS 63%

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by…

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21802EPSS 10%

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by…

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21803EPSS 8%

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by…

No fix yet
Fix from $1,600 2021-07-16
Webaccess MEDIUM 6.1
CVE-2021-34540

Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

No fix yet
Fix from $1,600 2021-06-11
Webaccess\/scada HIGH 7.8
CVE-2020-13554

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webv…

No fix yet
Fix from $1,950 2021-03-03
Webaccess\/scada HIGH 8.8
CVE-2020-13551

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In priv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13552

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In priv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13553

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13555

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM …

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 7.7
CVE-2020-13550

A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can…

No fix yet
Fix from $1,950 2021-02-17
Webaccess HIGH 7.5
CVE-2019-3942

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vu…

Mitigation only
Fix from $1,950 2020-04-01
Webaccess\/hmi Designer HIGH 7.5
CVE-2019-16899

In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000…

Mitigation only
Fix from $1,950 2019-09-26
Webaccess\/hmi Designer HIGH 7.5
CVE-2019-16900

Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

Mitigation only
Fix from $1,950 2019-09-26
Webaccess\/hmi Designer HIGH 7.5
CVE-2019-16901

Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!Rt…

Mitigation only
Fix from $1,950 2019-09-26