Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-10823EPSS 78% An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and D… Dwr 116 Firmware after 2.02 Fix from $1,9502018-10-17 HIGH 7.5 CVE-2018-10822EPSS 39% Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through … Dwr 116 Firmware after 2.02 Fix from $1,9502018-10-17 HIGH 8.8 CVE-2018-17442EPSS 14% An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endp… Central Wifimanager 1.03+ Fix from $1,9502018-10-08 MEDIUM 6.1 CVE-2018-17443EPSS 6% An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to… Central Wifimanager after 1.03 Fix from $1,6002018-10-08 CRITICAL 9.8 CVE-2018-17440EPSS 38% An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and ha… Central Wifimanager 1.03+ Fix from $2,3002018-10-08 MEDIUM 6.1 CVE-2018-17441EPSS 6% An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to st… Central Wifimanager after 1.03 Fix from $1,6002018-10-08 CRITICAL 9.8 CVE-2018-17063 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17064EPSS 7% An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17065 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17066EPSS 7% An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17067 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow … Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 CRITICAL 9.8 CVE-2018-17068 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-09-15 MEDIUM 5.4 CVE-2018-16605 D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page. Dir 600m Firmware No fix yet Fix from $1,6002018-09-12 HIGH 8.0 CVE-2018-12710EPSS 77% An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account… Dir 601 Firmware No fix yet Fix from $1,9502018-08-29 CRITICAL 9.8 CVE-2018-15839EPSS 45% D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. Dir 615 Firmware No fix yet Fix from $2,3002018-08-28 MEDIUM 6.1 CVE-2018-15874 Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Ta… Dir 615 Firmware Mitigation only Fix from $1,6002018-08-25 MEDIUM 6.1 CVE-2018-15875 Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via … Dir 615 Firmware Mitigation only Fix from $1,6002018-08-25 CRITICAL 9.8 CVE-2017-11563EPSS 5% D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions su… Eyeon Baby Monitor Firmware Mitigation only Fix from $2,3002018-08-24 HIGH 8.8 CVE-2017-11564 The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge ma… Eyeon Baby Monitor Firmware Mitigation only Fix from $1,9502018-08-24 CRITICAL 9.8 CVE-2016-6563EPSS 80% Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulner… Dir 823 Firmware No fix yet Fix from $2,3002018-07-13 MEDIUM 6.5 CVE-2018-12103 An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/… Dir 890l Firmware after 1.21b04beta01 Fix from $1,6002018-07-05 CRITICAL 9.8 CVE-2018-6210 D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attac… Dir 620 Firmware Mitigation only Fix from $2,3002018-06-19 CRITICAL 9.8 CVE-2018-8898EPSS 13% A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer… Dsl 3782 Firmware No fix yet Fix from $2,3002018-05-23 HIGH 8.8 CVE-2018-10957 CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affecte… Dir 868l Firmware No fix yet Fix from $1,9502018-05-10 HIGH 8.1 CVE-2018-10641 D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext. Dir 601 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2017-17020EPSS 15% On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware… Dcs 5009 Firmware after 1.14.09 Fix from $1,9502018-05-01 CRITICAL 9.8 CVE-2018-10106 D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdo… Dir 815 Firmware after 2.07.b01 Fix from $2,3002018-04-16 MEDIUM 6.1 CVE-2018-10107 D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info… Dir 815 Firmware after 2.07.b01 Fix from $1,6002018-04-16 MEDIUM 6.1 CVE-2018-10108 D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc… Dir 815 Firmware after 2.07.b01 Fix from $1,6002018-04-16 CRITICAL 9.8 CVE-2014-8888EPSS 5% The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via… Dir 815 Firmware Mitigation only Fix from $2,3002018-04-12