Vulnerability index

Browse CVEs

1,155 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-14414 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php. Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 MEDIUM 6.1 CVE-2017-14415 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php. Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 MEDIUM 6.1 CVE-2017-14416 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wandetect.php. Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 MEDIUM 5.9 CVE-2017-14419 The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW… Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 MEDIUM 5.9 CVE-2017-14420 The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW… Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 CRITICAL 9.8 CVE-2017-12943EPSS 39% D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path tra… Dir 600 B1 Firmware No fix yet Fix from $2,3002017-08-18 HIGH 7.5 CVE-2017-9675EPSS 12% On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot. Dir 605l Firmware No fix yet Fix from $1,9502017-06-15 HIGH 8.8 CVE-2017-9100EPSS 85% login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the… Dir 600m Firmware No fix yet Fix from $1,9502017-05-21 HIGH 7.5 CVE-2017-6190EPSS 18% Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arb… Dwr 116 Firmware No fix yet Fix from $1,9502017-04-10 HIGH 8.8 CVE-2017-6411 Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any p… Dsl 2730u Firmware No fix yet Fix from $1,9502017-03-06 CRITICAL 9.8 CVE-2016-10177EPSS 7% An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root … Dwr 932b Firmware No fix yet Fix from $2,3002017-01-30 CRITICAL 9.8 CVE-2016-10178EPSS 7% An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command. Dwr 932b Firmware No fix yet Fix from $2,3002017-01-30 CRITICAL 9.8 CVE-2016-10182EPSS 9% An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. Dwr 932b Firmware No fix yet Fix from $2,3002017-01-30 HIGH 7.5 CVE-2016-10179 An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10180 An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10181 An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10183EPSS 6% An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10184EPSS 6% An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10185 An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10186 An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 8.1 CVE-2016-10125 D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by h… Dgs 1100 Firmware No fix yet Fix from $1,9502017-01-09 MEDIUM 5.0 CVE-2011-4821 Directory traversal vulnerability in the TFTP server in D-Link DIR-601 Wireless N150 Home Router with firmware 1.02NA allows remote attackers to read… Dir 601 Firmware Mitigation only Fix from $1,6002014-06-20 MEDIUM 6.8 CVE-2014-3760 Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP 1150 with firmware 1.2.94 allow remote attackers to hijack the authenticatio… Dap 1150 Firmware No fix yet Fix from $1,6002014-05-16 HIGH 9.3 CVE-2013-4772 D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a d… Dir 826l Wireless N600 Cloud Router Firmware No fix yet Fix from $1,9502014-05-12 MEDIUM 5.4 CVE-2013-7308 The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2.20.B017 does not consider the possibility of duplicate Link State ID values… Des 3810 28 Firmware Mitigation only Fix from $1,6002014-01-23 HIGH 7.8 CVE-2013-5998 Unspecified vulnerability in the Web manager implementation on D-Link Japan DES-3800 devices with firmware before R4.50B58 allows remote attackers to… Des 3800 Firmware Mitigation only Fix from $1,9502013-11-22 MEDIUM 6.8 CVE-2013-5997 Unspecified vulnerability in the SSH implementation on D-Link Japan DES-3800 devices with firmware before R4.50B58 allows remote authenticated users … Des 3800 Firmware Mitigation only Fix from $1,6002013-11-22 MEDIUM 6.8 CVE-2013-5730 Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the aut… Dsl 2740b Firmware No fix yet Fix from $1,6002013-11-20 HIGH 7.6 CVE-2013-2271 The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and … Dsl 2740b Firmware No fix yet Fix from $1,9502013-11-19 HIGH 8.5 CVE-2013-6027 Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrat… Dir 100 No fix yet Fix from $1,9502013-10-19