Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webaccess CRITICAL 9.8
CVE-2016-0854EPSS 77%

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantec…

Fix: after 8.0
Fix from $2,300 2016-01-15
Webaccess HIGH 7.5
CVE-2016-0853

Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess HIGH 7.5
CVE-2016-0852

Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecif…

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess HIGH 7.5
CVE-2016-0851

Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess HIGH 8.1
CVE-2015-6467

Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess MEDIUM 5.4
CVE-2015-3948

Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML v…

Fix: after 8.0
Fix from $1,600 2016-01-15
Webaccess HIGH 8.1
CVE-2015-3947

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vec…

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess HIGH 8.8
CVE-2015-3946

Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified…

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess MEDIUM 5.3
CVE-2015-3943

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

Fix: after 8.0
Fix from $1,600 2016-01-15
Eki 1321 Series Firmware CRITICAL 9.8
CVE-2015-7938

Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.

Fix: after 2015-10-06
Fix from $2,300 2016-01-09
Eki 1321 Series Firmware HIGH 10.0
CVE-2015-6476

Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 h…

Fix: after 1.96
Fix from $1,950 2015-11-07
Webaccess MEDIUM 6.9
CVE-2014-9202

Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitra…

Mitigation only
Fix from $1,600 2015-09-28
Webaccess HIGH 10.0
CVE-2014-9208EPSS 9%

Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code v…

Fix: after 8.0
Fix from $1,950 2015-09-11
Eki 1200 Gateway Series Firmware HIGH 10.0
CVE-2014-8385

Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 1.62
Fix from $1,950 2015-02-13
Adamview HIGH 7.5
CVE-2014-8386EPSS 6%

Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) displa…

Fix: after 4.3
Fix from $1,950 2015-01-20
Webaccess HIGH 7.2
CVE-2014-8388

Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to execute arbitrary code via a c…

Fix: after 7.2
Fix from $1,950 2014-11-21
Eki 6340 Firmware HIGH 9.0
CVE-2014-8387EPSS 31%

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachar…

No fix yet
Fix from $1,950 2014-11-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0987

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0988

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0989

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0990

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserNa…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0991

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projec…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0992

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the passwo…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0985

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0986

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCm…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess HIGH 7.5
CVE-2014-2364EPSS 61%

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1)…

Fix: after 7.1
Fix from $1,950 2014-07-19
Advantech Webaccess MEDIUM 5.5
CVE-2014-2365

Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.

Fix: after 7.1
Fix from $1,600 2014-07-19
Advantech Webaccess MEDIUM 5.0
CVE-2014-2368

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a craft…

Fix: after 7.1
Fix from $1,600 2014-07-19
Advantech Webaccess HIGH 7.5
CVE-2014-0763EPSS 19%

An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll is exposed through SOAP inter…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess HIGH 7.5
CVE-2014-0764

By providing an overly long string to the NodeName parameter, an attacker may be able to overflow the static stack buffer. The attacker may then ex…

Fix: after 7.1
Fix from $1,950 2014-04-12