Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-10823 A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allo… Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 CRITICAL 9.8 CVE-2020-10824 A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 a… Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 CRITICAL 9.8 CVE-2020-10825 A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices … Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 CRITICAL 9.8 CVE-2020-10826EPSS 39% /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a … Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 CRITICAL 9.8 CVE-2020-10827EPSS 21% A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exe… Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 CRITICAL 9.8 CVE-2020-10828EPSS 21% A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exe… Vigor300b Firmware 1.5.1+ Fix from $2,3002020-03-26 CRITICAL 9.8 CVE-2020-8515 KEVEPSS 100% DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo… Vigor2960 Firmware Mitigation only Fix from $2,3002020-02-01 MEDIUM 6.1 CVE-2019-16533 On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an… Vigor2925 Firmware Mitigation only Fix from $1,6002019-09-20 MEDIUM 6.1 CVE-2019-16534 On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life produ… Vigor2925 Firmware Mitigation only Fix from $1,6002019-09-20 HIGH 8.8 CVE-2017-11649 Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack… Vigorap 910c Firmware No fix yet Fix from $1,9502018-03-07 MEDIUM 6.1 CVE-2017-11650 Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitr… Vigorap 910c Firmware No fix yet Fix from $1,6002018-03-07 MEDIUM 6.8 CVE-2013-5703 The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted… Vigor 2700 Router Firmware Mitigation only Fix from $1,6002013-10-22