Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2024-44844
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct…
Vigor3900 Firmware
No fix yet
HIGH 8.8
CVE-2024-44845
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu…
Vigor3900 Firmware
No fix yet
HIGH 8.0
CVE-2024-43027
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to conta…
Vigor300b Firmware
1.5.1.5+
HIGH 7.5
CVE-2024-23721
A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the fu…
Vigor3910 Firmware
after 4.3.2.5
CRITICAL 9.8
CVE-2023-47254
An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and esca…
Vigor167 Firmware
No fix yet
HIGH 8.1
CVE-2023-6265
** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'op…
Vigor2960 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-31447
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to m…
Vigor2620 Firmware
3.9.8.4+
CRITICAL 9.8
CVE-2023-33778
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and …
Myvigor
2.3.2 / 2.6.7+
HIGH 7.8
CVE-2023-24229EPSS 7%
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v…
Vigor2960 Firmware
No fix yet
MEDIUM 6.1
CVE-2023-23313
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web applica…
Vigor2860 Firmware
3.9.4+
HIGH 8.8
CVE-2023-1162EPSS 26%
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an un…
Vigor 2960 Firmware
No fix yet
MEDIUM 6.5
CVE-2023-1163
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul…
Vigor 2960 Firmware
No fix yet
MEDIUM 5.5
CVE-2023-1009EPSS 16%
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function…
Vigor2960 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-32548EPSS 34%
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer over…
Vigor3910 Firmware
4.3.1.1 / 4.4.0+
CRITICAL 9.8
CVE-2021-42911
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfu…
Vigor2960 Firmware
after 1.5.1.3
CRITICAL 9.8
CVE-2021-43118EPSS 35%
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a craft…
Vigor2960 Firmware
No fix yet
MEDIUM 5.4
CVE-2020-28968
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vul…
Vigorap 1000c Firmware
No fix yet
CRITICAL 9.8
CVE-2021-20125
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect…
Vigorconnect
No fix yet
HIGH 8.8
CVE-2021-20126
Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent …
Vigorconnect
No fix yet
HIGH 8.1
CVE-2021-20127
An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This …
Vigorconnect
No fix yet
HIGH 7.5
CVE-2021-20123 KEVEPSS 75%
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. …
Vigorconnect
Mitigation only
HIGH 7.5
CVE-2021-20124 KEVEPSS 71%
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauth…
Vigorconnect
Mitigation only
HIGH 7.5
CVE-2021-20129
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
Vigorconnect
No fix yet
MEDIUM 5.4
CVE-2021-20128
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input…
Vigorconnect
No fix yet
HIGH 8.8
CVE-2020-19664EPSS 5%
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
Vigor2960 Firmware
after 1.5.1
CRITICAL 9.8
CVE-2020-15415 KEVEPSS 85%
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell …
Vigor3900 Firmware
1.5.1+
CRITICAL 9.8
CVE-2020-14473
Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.
Vigor300b Firmware
1.5.1.1+
CRITICAL 9.8
CVE-2020-14472
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
Vigor300b Firmware
1.5.1.1+
CRITICAL 9.8
CVE-2020-14993EPSS 5%
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code…
Vigor300b Firmware
1.5.1.1+
HIGH 7.5
CVE-2020-3932
A vulnerable SNMP in Draytek VigorAP910C cannot be disabled, which may cause information leakage.
Vigorap 910c Firmware
Mitigation only