Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-34025 CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing … Powerpanel after 4.9.0 Fix from $2,3002024-05-15 CRITICAL 9.8 CVE-2024-32047 Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining acce… Powerpanel after 4.9.0 Fix from $2,3002024-05-15 CRITICAL 9.8 CVE-2024-32053 Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could… Powerpanel after 4.9.0 Fix from $2,3002024-05-15 CRITICAL 9.8 CVE-2024-33625 CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypas… Powerpanel after 4.9.0 Fix from $2,3002024-05-15 HIGH 8.8 CVE-2024-31856 An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injec… Powerpanel after 4.9.0 Fix from $1,9502024-05-15 HIGH 7.5 CVE-2024-31409 Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the sy… Powerpanel after 4.9.0 Fix from $1,9502024-05-15 HIGH 7.5 CVE-2024-32042 The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be … Powerpanel after 4.9.0 Fix from $1,9502024-05-15 MEDIUM 6.5 CVE-2024-31410 The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to im… Powerpanel after 4.9.0 Fix from $1,6002024-05-15 HIGH 7.5 CVE-2024-32737EPSS 5% A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor… Powerpanel 2.8.3+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-32738 A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor… Powerpanel 2.8.3+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-32739EPSS 5% A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor… Powerpanel 2.8.3+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-32735EPSS 7% An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote… Powerpanel 2.8.3+ Fix from $2,3002024-05-14 HIGH 7.5 CVE-2024-32736EPSS 5% A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor… Powerpanel 2.8.3+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2023-3266 A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP… Powerpanel Server 2.6.9+ Fix from $2,3002023-08-14 HIGH 8.8 CVE-2023-3267 When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without… Powerpanel Server 2.6.9+ Fix from $1,9502023-08-14 CRITICAL 9.8 CVE-2023-3264 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres… Powerpanel Server 1.44.0804202 / 2.6.9+ Fix from $2,3002023-08-14 CRITICAL 9.8 CVE-2023-3265 An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to… Powerpanel Server 2.6.9+ Fix from $2,3002023-08-14 HIGH 8.8 CVE-2023-3260 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An au… Powerpanel Server 1.44.0804202 / 2.6.9+ Fix from $1,9502023-08-14 HIGH 7.2 CVE-2023-3261 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Suc… Powerpanel Server 1.44.0804202 / 2.6.9+ Fix from $1,9502023-08-14 CRITICAL 9.8 CVE-2023-25133 Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Busine… Powerpanel after 4.8.6 Fix from $2,3002023-04-24 CRITICAL 9.8 CVE-2023-25131 Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows … Powerpanel after 4.8.6 Fix from $2,3002023-04-24 CRITICAL 9.8 CVE-2023-25132 Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,… Powerpanel after 4.8.6 Fix from $2,3002023-04-24