Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2016-0854EPSS 77% Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantec… Webaccess after 8.0 Fix from $2,3002016-01-15 HIGH 7.5 CVE-2016-0853 Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input. Webaccess after 8.0 Fix from $1,9502016-01-15 HIGH 7.5 CVE-2016-0852 Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecif… Webaccess after 8.0 Fix from $1,9502016-01-15 HIGH 7.5 CVE-2016-0851 Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors. Webaccess after 8.0 Fix from $1,9502016-01-15 HIGH 8.1 CVE-2015-6467 Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin. Webaccess after 8.0 Fix from $1,9502016-01-15 MEDIUM 5.4 CVE-2015-3948 Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML v… Webaccess after 8.0 Fix from $1,6002016-01-15 HIGH 8.1 CVE-2015-3947 SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vec… Webaccess after 8.0 Fix from $1,9502016-01-15 HIGH 8.8 CVE-2015-3946 Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified… Webaccess after 8.0 Fix from $1,9502016-01-15 MEDIUM 5.3 CVE-2015-3943 Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors. Webaccess after 8.0 Fix from $1,6002016-01-15 CRITICAL 9.8 CVE-2015-7938 Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors. Eki 1321 Series Firmware after 2015-10-06 Fix from $2,3002016-01-09 HIGH 10.0 CVE-2015-6476 Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 h… Eki 1321 Series Firmware after 1.96 Fix from $1,9502015-11-07 MEDIUM 6.9 CVE-2014-9202 Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitra… Webaccess Mitigation only Fix from $1,6002015-09-28 HIGH 10.0 CVE-2014-9208EPSS 9% Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code v… Webaccess after 8.0 Fix from $1,9502015-09-11 HIGH 10.0 CVE-2014-8385 Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors. Eki 1200 Gateway Series Firmware after 1.62 Fix from $1,9502015-02-13 HIGH 7.5 CVE-2014-8386EPSS 6% Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) displa… Adamview after 4.3 Fix from $1,9502015-01-20 HIGH 7.2 CVE-2014-8388 Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to execute arbitrary code via a c… Webaccess after 7.2 Fix from $1,9502014-11-21 HIGH 9.0 CVE-2014-8387EPSS 31% cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachar… Eki 6340 Firmware No fix yet Fix from $1,9502014-11-20 MEDIUM 6.8 CVE-2014-0987 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0988 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0989 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0990 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserNa… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0991 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projec… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0992 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the passwo… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0985 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0986 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCm… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 HIGH 7.5 CVE-2014-2364EPSS 61% Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1)… Advantech Webaccess after 7.1 Fix from $1,9502014-07-19 MEDIUM 5.5 CVE-2014-2365 Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors. Advantech Webaccess after 7.1 Fix from $1,6002014-07-19 MEDIUM 5.0 CVE-2014-2368 The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a craft… Advantech Webaccess after 7.1 Fix from $1,6002014-07-19 HIGH 7.5 CVE-2014-0763EPSS 19% An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll is exposed through SOAP inter… Advantech Webaccess after 7.1 Fix from $1,9502014-04-12 HIGH 7.5 CVE-2014-0764 By providing an overly long string to the NodeName parameter, an attacker may be able to overflow the static stack buffer. The attacker may then ex… Advantech Webaccess after 7.1 Fix from $1,9502014-04-12