Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2019-15392
The Asus ZenFone 4 Selfie Android device with a build fingerprint of Android/sdm660_64/sdm660_64:8.1.0/OPM1/14.2016.1802.247-20180419:user/release-ke…
Zenfone 4 Selfie Firmware
Mitigation only
CRITICAL 9.8
CVE-2013-4656
Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.
Rt Ac66u Firmware
Mitigation only
MEDIUM 6.8
CVE-2019-18216
The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which …
Rog Zephyrus M Gm501gs Firmware
Mitigation only
HIGH 7.5
CVE-2018-20336
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a l…
Asuswrt Merlin
No fix yet
CRITICAL 9.8
CVE-2019-10709EPSS 12%
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potent…
Precision Touchpad
No fix yet
CRITICAL 9.8
CVE-2018-14714EPSS 27%
System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" …
Rt Ac3200 Firmware
No fix yet
HIGH 8.1
CVE-2018-14713
Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU r…
Rt Ac3200 Firmware
No fix yet
MEDIUM 6.5
CVE-2018-14711
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing acti…
Rt Ac3200 Firmware
No fix yet
MEDIUM 6.5
CVE-2018-14712
Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter.
Rt Ac3200 Firmware
No fix yet
MEDIUM 6.1
CVE-2018-14710EPSS 5%
Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter.
Rt Ac3200 Firmware
No fix yet
HIGH 7.8
CVE-2018-14993
The ASUS Zenfone V Live Android device with a build fingerprint of asus/VZW_ASUS_A009/ASUS_A009:7.1.1/NMF26F/14.0610.1802.78-20180313:user/release-ke…
Zenfone V Live Firmware
Mitigation only
HIGH 7.1
CVE-2018-14980
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-k…
Zenfone 3 Max Firmware
Mitigation only
MEDIUM 5.5
CVE-2018-14992
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-k…
Zenfone 3 Max Firmware
No fix yet
HIGH 7.8
CVE-2018-18535
The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This c…
Aura Sync Firmware
No fix yet
HIGH 7.8
CVE-2018-18536
The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could …
Aura Sync Firmware
No fix yet
MEDIUM 5.5
CVE-2018-18537
The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.
Aura Sync Firmware
No fix yet
MEDIUM 6.1
CVE-2018-18291
A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML v…
Rt Ac58u Firmware
No fix yet
MEDIUM 5.3
CVE-2018-18287
On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source …
Rt Ac58u Firmware
No fix yet
HIGH 8.8
CVE-2018-15887
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execu…
Dsl N12e C1 Firmware
No fix yet
HIGH 7.5
CVE-2018-11492EPSS 11%
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
Hg100 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-8826
ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N…
Rt Ac51u Firmware
Mitigation only
HIGH 8.8
CVE-2017-12592
ASUS DSL-N10S V2.1.16_APAC devices have a privilege escalation vulnerability. A normal user can escalate its privilege and perform administrative act…
Dsl N10s Firmware
No fix yet
HIGH 8.8
CVE-2017-12593
ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.
Dsl N10s Firmware
No fix yet
MEDIUM 5.4
CVE-2017-12591
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.
Dsl N10s Firmware
No fix yet
MEDIUM 6.5
CVE-2017-8877
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.
Rt Ac1750 Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-8878
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.
Rt Ac1750 Firmware
Mitigation only
CRITICAL 9.8
CVE-2013-4659EPSS 14%
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on rout…
Rt Ac66u Firmware
No fix yet
CRITICAL 9.8
CVE-2017-6548EPSS 21%
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-A…
Rt Ac53 Firmware
No fix yet
HIGH 8.8
CVE-2017-6549EPSS 8%
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87…
Rt Ac53 Firmware
No fix yet
MEDIUM 6.1
CVE-2017-6547
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC…
Rt Ac53 Firmware
No fix yet