Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2021-33032EPSS 52%
A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 fi…
Homematic Ccu2 Firmware
after 3.57.5
CRITICAL 9.8
CVE-2020-12834EPSS 11%
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, …
Homematic Ccu2 Firmware
after 3.51.6
HIGH 8.8
CVE-2019-14423EPSS 20%
A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated…
Cux Daemon
after 2.45.6
HIGH 8.8
CVE-2019-15850EPSS 16%
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute …
Homematic Ccu3 Firmware
No fix yet
HIGH 7.3
CVE-2019-15849
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs i…
Homematic Ccu3 Firmware
No fix yet
MEDIUM 6.5
CVE-2019-14424
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated …
Cux Daemon
after 2.45.6
CRITICAL 9.8
CVE-2019-16199EPSS 9%
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface …
Homematic Ccu2 Firmware
2.47.18 / 3.47.18+
CRITICAL 9.8
CVE-2019-9584
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting…
Homematic Ccu2 Firmware
after 3.47.15
CRITICAL 9.8
CVE-2019-9585
eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res…
Homematic Ccu2 Firmware
2.47.10 / 3.47.10+
HIGH 8.2
CVE-2019-9583
eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected ve…
Homematic Ccu3 Firmware
No fix yet
HIGH 7.5
CVE-2019-9582
eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7…
Homematic Ccu2 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-14985EPSS 8%
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…
Homematic Ccu2 Firmware
No fix yet
HIGH 8.1
CVE-2019-14984EPSS 6%
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to t…
Homematic Ccu2 Firmware
after 1.2.0
HIGH 8.1
CVE-2019-14986
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to t…
Homematic Ccu2 Firmware
2.3.0+
HIGH 7.5
CVE-2019-14474
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to star…
Ccu3 Firmware
after 3.47.15
HIGH 8.8
CVE-2019-14473
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level accoun…
Ccu2 Firmware
after 3.47.15
HIGH 7.5
CVE-2019-14475
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can ob…
Ccu2 Firmware
after 3.47.15
CRITICAL 9.8
CVE-2019-10119
eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attack…
Ccu3 Firmware
2.41.8 / 3.43.16+
CRITICAL 9.8
CVE-2019-10121
eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attack…
Ccu3 Firmware
2.41.8 / 3.43.15+
CRITICAL 9.8
CVE-2019-10122
eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Server 2.0 component, aka H…
Ccu3 Firmware
2.41.9 / 3.43.16+
HIGH 8.8
CVE-2019-10120
On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by con…
Ccu3 Firmware
2.41.8 / 3.43.16+
HIGH 7.5
CVE-2019-9727
Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retri…
Ccu3 Firmware
after 3.43.15
HIGH 7.5
CVE-2019-9726EPSS 16%
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device…
Ccu3 Firmware
after 3.43.15
CRITICAL 9.8
CVE-2018-7301
eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests …
Homematic Central Control Unit Ccu2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-7300EPSS 31%
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows…
Homematic Ccu2 Firmware
after 2.29.22
HIGH 8.1
CVE-2018-7298
In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protoco…
Homematic Central Control Unit Ccu2 Firmware
Mitigation only
HIGH 8.0
CVE-2018-7299
Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticated attackers to create or over…
Homematic Central Control Unit Ccu2 Firmware
after 2.29.22
CRITICAL 9.8
CVE-2018-7297EPSS 64%
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access …
Homematic Central Control Unit Ccu2 Firmware
after 2.29.22
MEDIUM 5.3
CVE-2018-7296
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the…
Homematic Central Control Unit Ccu2 Firmware
after 2.29.22