Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-3040EPSS 9%
A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload…
Vigor300b Firmware
after 1.5.1.6
CRITICAL 9.8
CVE-2024-51138
Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133…
Vigor3912 Firmware
3.9.8.3 / 3.9.9.1+
CRITICAL 9.8
CVE-2024-51139
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and…
Vigor2620 Firmware
3.9.8.3 / 3.9.9.1+
HIGH 8.8
CVE-2024-41334
Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9…
Vigor166 Firmware
3.9.7 / 3.9.8+
HIGH 8.8
CVE-2024-41339
An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vi…
Vigor165 Firmware
3.9.8 / 3.9.8.9+
HIGH 8.4
CVE-2024-41340
An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 pri…
Vigor165 Firmware
3.9.8 / 3.9.8.9+
HIGH 7.5
CVE-2024-41338
A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, V…
Vigor165 Firmware
3.9.7 / 3.9.8.8+
CRITICAL 9.8
CVE-2024-12987 KEVEPSS 98%
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file …
Vigor300b Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-12986EPSS 33%
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown…
Vigor300b Firmware
1.5.1.5+
HIGH 8.0
CVE-2024-45885
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45887
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45888
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45889
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45890
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cg…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45891
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45893
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45882
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-45884
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51246
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP func…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51249
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot func…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51251
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup func…
Vigor3900 Firmware
Mitigation only
HIGH 8.0
CVE-2024-51253
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP func…
Vigor3900 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-51252
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51244
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec fun…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51245
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_tabl…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51247
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo func…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-51248
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow f…
Vigor3900 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-51255
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_…
Vigor3900 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-51260
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_proc…
Vigor3900 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-51259
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cac…
Vigor3900 Firmware
Mitigation only