Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webaccess\/vpn MEDIUM 6.5
CVE-2025-34238

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConf…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34240

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an au…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 5.4
CVE-2025-34236

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). …

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 5.4
CVE-2025-34237

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStand…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Iview HIGH 7.2
CVE-2022-50595

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $1,950 2025-11-06
Iview CRITICAL 9.8
CVE-2022-50591

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $2,300 2025-11-06
Iview CRITICAL 9.8
CVE-2022-50593

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $2,300 2025-11-06
Iview HIGH 7.5
CVE-2022-50594

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $1,950 2025-11-06
Iview HIGH 7.2
CVE-2022-50592

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $1,950 2025-11-06
Iview HIGH 8.8
CVE-2025-53515

A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue …

Fix: 5.7.05.7057+
Fix from $1,950 2025-07-11
Iview MEDIUM 6.5
CVE-2025-53509

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authen…

Fix: 5.7.05.7057+
Fix from $1,600 2025-07-11
Iview MEDIUM 5.4
CVE-2025-53519

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By …

Fix: 5.7.05.7057+
Fix from $1,600 2025-07-11
Iview HIGH 8.8
CVE-2025-53475

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). Th…

Fix: 5.7.05.7057+
Fix from $1,950 2025-07-11
Iview HIGH 8.8
CVE-2025-52577

A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This …

Fix: 5.7.05.7057+
Fix from $1,950 2025-07-11
Iview MEDIUM 6.1
CVE-2025-53397

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By …

Fix: 5.7.05.7057+
Fix from $1,600 2025-07-11
Iview HIGH 7.6
CVE-2025-48891

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability ca…

Fix: 5.7.05.7057+
Fix from $1,950 2025-07-11
Iview MEDIUM 5.4
CVE-2025-41442

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By …

Fix: 5.7.05.7057+
Fix from $1,600 2025-07-11
Wise 4060lan Firmware CRITICAL 9.6
CVE-2025-48469

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially lea…

No fix yet
Fix from $2,300 2025-06-24
Wise 4060lan Firmware HIGH 8.1
CVE-2025-48466

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs…

No fix yet
Fix from $1,950 2025-06-24
Wise 4010lan Firmware MEDIUM 6.5
CVE-2025-48467

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and s…

No fix yet
Fix from $1,600 2025-06-24
Wise 4010lan Firmware MEDIUM 6.4
CVE-2025-48468

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

Mitigation only
Fix from $1,600 2025-06-24
Wise 4060lan Firmware MEDIUM 5.0
CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the sess…

Mitigation only
Fix from $1,600 2025-06-24
Eki 6333ac 2g Firmware MEDIUM 6.5
CVE-2024-50377

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-633…

Fix: 1.2.2 / 1.6.5+
Fix from $1,600 2024-11-26
Eki 6333ac 2g Firmware MEDIUM 5.2
CVE-2024-50376

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufa…

Fix: 1.2.2 / 1.6.5+
Fix from $1,600 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50374

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50375

A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50371

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50372

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50373

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50370

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26