Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-15850EPSS 16%
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute …
Homematic Ccu3 Firmware
No fix yet
HIGH 7.3
CVE-2019-15849
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs i…
Homematic Ccu3 Firmware
No fix yet
HIGH 8.2
CVE-2019-9583
eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected ve…
Homematic Ccu3 Firmware
No fix yet
HIGH 7.5
CVE-2019-9582
eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7…
Homematic Ccu2 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-14985EPSS 8%
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…
Homematic Ccu2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-7301
eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests …
Homematic Central Control Unit Ccu2 Firmware
Mitigation only
HIGH 8.1
CVE-2018-7298
In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protoco…
Homematic Central Control Unit Ccu2 Firmware
Mitigation only