Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-10215EPSS 5% An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame… Dir 825 Firmware No fix yet Fix from $1,9502020-03-07 HIGH 8.8 CVE-2020-10216EPSS 5% An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s… Dir 825 Firmware No fix yet Fix from $1,9502020-03-07 HIGH 7.8 CVE-2019-20499EPSS 95% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the … Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 HIGH 7.8 CVE-2019-20500 KEVEPSS 97% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web… Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 HIGH 7.8 CVE-2019-20501EPSS 90% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web i… Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 HIGH 7.5 CVE-2019-19224 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the confi… Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 HIGH 7.5 CVE-2019-19225 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers… Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 HIGH 7.5 CVE-2019-19226 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable … Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 HIGH 7.5 CVE-2019-19223 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router … Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 MEDIUM 5.4 CVE-2019-19222 A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaSc… Dsl 2680 Firmware No fix yet Fix from $1,6002020-03-04 HIGH 8.8 CVE-2020-9534 fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed. Dir 615jx10 Firmware No fix yet Fix from $1,9502020-03-02 HIGH 8.8 CVE-2020-9535 fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malforme… Dir 615jx10 Firmware No fix yet Fix from $1,9502020-03-02 HIGH 8.8 CVE-2020-8861EPSS 7% This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range e… Dap 1330 Firmware 1.10b01+ Fix from $1,9502020-02-22 HIGH 8.8 CVE-2020-8862EPSS 13% This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 router… Dap 2610 Firmware after 2.01rc067 Fix from $1,9502020-02-22 CRITICAL 9.8 CVE-2020-6841 D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.ph… Dch M225 Firmware after 1.05b01 Fix from $2,3002020-02-21 HIGH 7.2 CVE-2020-6842 D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media … Dch M225 Firmware after 1.05b01 Fix from $1,9502020-02-21 HIGH 7.2 CVE-2012-6614 D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by ov… Dsr 250n Firmware 1.08b31+ Fix from $1,9502020-02-19 CRITICAL 9.8 CVE-2020-8962 A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when hand… Dir 842 Firmware No fix yet Fix from $2,3002020-02-13 CRITICAL 9.8 CVE-2013-5945EPSS 10% Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N wi… Dsr 150 Firmware 1.05b64 / 1.08b44+ Fix from $2,3002020-02-11 MEDIUM 5.9 CVE-2013-3096 D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability. Dir865l Firmware No fix yet Fix from $1,6002020-02-07 CRITICAL 9.8 CVE-2013-7055EPSS 7% D-Link DIR-100 4.03B07 has PPTP and poe information disclosure Dir 100 Firmware No fix yet Fix from $2,3002020-02-04 MEDIUM 6.1 CVE-2013-7054 D-Link DIR-100 4.03B07: cli.cgi XSS Dir 100 Firmware No fix yet Fix from $1,6002020-02-04 CRITICAL 9.8 CVE-2013-7052EPSS 25% D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script Dir 100 Firmware No fix yet Fix from $2,3002020-02-04 HIGH 8.8 CVE-2013-7051EPSS 16% D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters Dir 100 Firmware No fix yet Fix from $1,9502020-02-04 HIGH 8.8 CVE-2013-7053 D-Link DIR-100 4.03B07: cli.cgi CSRF Dir 100 Firmware No fix yet Fix from $1,9502020-02-04 CRITICAL 9.8 CVE-2019-20215EPSS 75% D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi()… Dir 859 Firmware Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2019-20216 D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi… Dir 859 Firmware Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2019-20217 D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi… Dir 859 Firmware Patch available Fix from $2,3002020-01-29 HIGH 7.5 CVE-2013-1602EPSS 15% An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01,… Dcs 3411 Firmware No fix yet Fix from $1,9502020-01-28 MEDIUM 5.3 CVE-2013-1603EPSS 16% An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, D… Dcs 3411 Firmware No fix yet Fix from $1,6002020-01-28