Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Central Wifimanager CRITICAL 9.8
CVE-2019-13372EPSS 82%

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PH…

Fix: after 1.03
Fix from $2,300 2019-07-06
Central Wifimanager CRITICAL 9.8
CVE-2019-13373EPSS 68%

An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statement…

Patch available
Fix from $2,300 2019-07-06
Central Wifimanager CRITICAL 9.8
CVE-2019-13375EPSS 28%

A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcode…

Patch available
Fix from $2,300 2019-07-06
Central Wifimanager MEDIUM 6.1
CVE-2019-13374

A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 al…

Patch available
Fix from $1,600 2019-07-06
Dcs 1130 Firmware CRITICAL 9.8
CVE-2017-8415

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the pas…

No fix yet
Fix from $2,300 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8412EPSS 6%

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom binary called mp4ts under the /var/www/video folder. It seem…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8413EPSS 10%

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and lis…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8416EPSS 12%

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and lis…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1100 Firmware HIGH 8.8
CVE-2017-8417

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device requires that a user logging into the device provide a username and passw…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1100 Firmware CRITICAL 9.8
CVE-2017-8410EPSS 6%

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections rece…

No fix yet
Fix from $2,300 2019-07-02
Dcs 1100 Firmware HIGH 7.8
CVE-2017-8414

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary orthrus in /sbin folder of the device handles all the UPnP connections re…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 7.5
CVE-2017-8409

An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a username and password. However…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8406

An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. …

No fix yet
Fix from $1,950 2019-07-02
Dcs 1100 Firmware HIGH 7.5
CVE-2017-8405

An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections rece…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware CRITICAL 9.8
CVE-2017-8404EPSS 8%

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…

No fix yet
Fix from $2,300 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8407

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the we…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8411EPSS 6%

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware CRITICAL 9.8
CVE-2017-8408EPSS 5%

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings re…

No fix yet
Fix from $2,300 2019-07-02
Dir 823g Firmware HIGH 8.8
CVE-2019-13128EPSS 8%

An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via…

No fix yet
Fix from $1,950 2019-07-01
Dir 300 Firmware CRITICAL 9.8
CVE-2013-7471EPSS 24%

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 r…

Fix: 1.02b03 / 1.04b11+
Fix from $2,300 2019-06-11
Dir 818lw Firmware HIGH 8.8
CVE-2019-12786

An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML in…

No fix yet
Fix from $1,950 2019-06-10
Dir 818lw Firmware HIGH 8.8
CVE-2019-12787

An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML in…

No fix yet
Fix from $1,950 2019-06-10
Dcs 930l Firmware HIGH 8.8
CVE-2019-10999

The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely aut…

Fix: after 2.17.01
Fix from $1,950 2019-05-06
Dsl 3782 Firmware HIGH 8.8
CVE-2018-17990

An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated…

No fix yet
Fix from $1,950 2019-04-01
Dsl 3782 Firmware MEDIUM 5.4
CVE-2018-17989

A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a …

No fix yet
Fix from $1,600 2019-04-01
Dir 817lw Firmware HIGH 7.5
CVE-2019-7642

D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS quer…

No fix yet
Fix from $1,950 2019-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2019-10039

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $2,300 2019-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2019-10040

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $2,300 2019-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2019-10041

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $2,300 2019-03-25
Dir 816 Firmware HIGH 7.5
CVE-2019-10042

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $1,950 2019-03-25