Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2024-21878
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) all…
Iq Gateway Firmware
8.2.4225+
HIGH 8.8
CVE-2024-21879
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoin…
Iq Gateway Firmware
8.2.4225+
HIGH 7.2
CVE-2024-21880
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint i…
Iq Gateway Firmware
after 7.3.120
CRITICAL 9.1
CVE-2024-21876
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly know…
Iq Gateway Firmware
8.2.4225+
MEDIUM 6.5
CVE-2024-21877
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly …
Iq Gateway Firmware
8.2.4225+
CRITICAL 9.8
CVE-2023-33869
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.
Envoy Firmware
Mitigation only
HIGH 7.5
CVE-2023-32274
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this…
Installer Toolkit
Mitigation only
HIGH 8.8
CVE-2020-25755
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows rem…
Envoy Firmware
No fix yet
HIGH 7.5
CVE-2020-25754
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional use…
Envoy Firmware
No fix yet
CRITICAL 9.8
CVE-2020-25753
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial…
Envoy Firmware
No fix yet
MEDIUM 5.3
CVE-2020-25752
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts.…
Envoy Firmware
No fix yet
CRITICAL 9.8
CVE-2019-7678
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.
Envoy
after 3.9.0
HIGH 7.2
CVE-2019-7676
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.
Envoy
after 3.9.0
MEDIUM 6.1
CVE-2019-7677
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
Envoy
after 3.9.0