Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2024-50369
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50367
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50368
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50365
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50366
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50362
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50363
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50364
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50360
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50361
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50359
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
HIGH 7.2
CVE-2024-50358
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2…
Eki 6333ac 1gpo Firmware
1.2.2 / 1.6.5+
HIGH 7.5
CVE-2023-52335
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensi…
Iview
5.7.04.6752+
HIGH 8.8
CVE-2024-39275
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a
session is closed. Forging requests with a legitimate cooki…
Adam 5630 Firmware
2.5.2+
HIGH 8.8
CVE-2024-28948
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same
origin policy, w…
Adam 5630 Firmware
2.5.2+
MEDIUM 6.1
CVE-2024-38308
Advantech ADAM 5550's web application includes a "logs" page where all
the HTTP requests received are displayed to the user. The device doesn't
cor…
Adam 5550 Firmware
Mitigation only
MEDIUM 5.7
CVE-2024-34542
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
Adam 5630 Firmware
2.5.2+
MEDIUM 5.7
CVE-2024-37187
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
Adam 5550 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-5642EPSS 17%
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…
R Seenet
No fix yet
HIGH 7.5
CVE-2023-4215
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentia…
Webaccess
No fix yet
MEDIUM 5.4
CVE-2023-4203
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by au…
Eki 1524 Firmware
after 1.24
MEDIUM 5.4
CVE-2023-4202
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by au…
Eki 1524 Firmware
after 1.21
CRITICAL 9.8
CVE-2023-1437
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain…
Webaccess\/scada
9.1.4+
HIGH 8.8
CVE-2023-3983EPSS 17%
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypa…
Iview
5.7.4.6752+
CRITICAL 9.8
CVE-2023-2611
Advantech R-SeeNet
versions 2.4.22
is installed with a hidden root-level user that is not available in the
users list. This hidden user has a pas…
R Seenet
after 2.4.22
HIGH 8.1
CVE-2023-3256
Advantech R-SeeNet
versions 2.4.22
allows low-level users to access and load the content of local files.
R Seenet
after 2.4.22
HIGH 7.8
CVE-2023-2866
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could…
Webaccess
Mitigation only
CRITICAL 9.8
CVE-2023-32540
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file…
Webaccess\/scada
after 9.1.3
CRITICAL 9.8
CVE-2023-32628
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extensi…
Webaccess\/scada
after 9.1.3
HIGH 7.2
CVE-2023-22450
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script fi…
Webaccess\/scada
after 9.1.3