Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-59174
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted me…
Packet Core Controller
1.39+
MEDIUM 6.5
CVE-2026-25659
Ericsson
Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling
of Missing Values (CWE-230) vulnerability where an attacker co…
Packet Core Gateway
1.30+
MEDIUM 6.5
CVE-2026-25657
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability whe…
Packet Core Gateway
1.30+
MEDIUM 6.5
CVE-2026-25658
Ericsson
Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling
of Missing Values (CWE-230) vulnerability where an attacker co…
Packet Core Gateway
1.30+
CRITICAL 9.8
CVE-2026-25660
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication bypass occurs …
Codechecker
6.27.4+
MEDIUM 5.3
CVE-2024-53828
Ericsson Packet Core Controller (PCC) versions prior
to 1.38 contain a vulnerability where an attacker sending a large volume of
specially crafted me…
Packet Core Controller
after 1.38
HIGH 7.5
CVE-2025-27260
Ericsson
Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special
Elements vulnerability which, if exploited, can lead…
Indoor Connect 8855 Firmware
2025.q3+
MEDIUM 6.1
CVE-2025-40842
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a
Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to
unauthori…
Indoor Connect 8855 Firmware
2025.q3+
HIGH 7.8
CVE-2025-40843
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
CodeChecker versions up t…
Codechecker
6.26.2+
CRITICAL 9.8
CVE-2025-27258
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Network Manager
25.1+
MEDIUM 5.4
CVE-2025-27259
Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to…
Network Manager
25.2+
CRITICAL 9.8
CVE-2025-40836
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with es…
Indoor Connect 8855 Firmware
2025.q2+
HIGH 8.8
CVE-2025-40837
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher p…
Indoor Connect 8855 Firmware
2025.q2+
HIGH 7.5
CVE-2025-40838
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unautho…
Indoor Connect 8855 Firmware
2025.q2+
HIGH 7.8
CVE-2025-27262
Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.
Indoor Connect 8855 Firmware
2025.q2+
CRITICAL 9.8
CVE-2025-27261
Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.
Indoor Connect 8855 Firmware
2025.q2+
MEDIUM 6.1
CVE-2025-1300
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
The CodeChecker web server c…
Codechecker
6.24.6+
HIGH 8.2
CVE-2024-53829
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Cross-site request forgery al…
Codechecker
6.24.5+
CRITICAL 10.0
CVE-2024-10081EPSS 39%
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication bypass occurs …
Codechecker
6.24.2+
CRITICAL 9.0
CVE-2024-10082
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication method confusi…
Codechecker
6.24.2+
MEDIUM 6.5
CVE-2023-49793
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the serv…
Codechecker
6.23.0+
HIGH 7.1
CVE-2024-25007
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralizat…
Network Manager
23.1+
HIGH 8.8
CVE-2023-39909
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
Network Manager
23.2+
HIGH 8.8
CVE-2022-47531
An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass s…
Evolved Packet Gateway
2.16 / 3.25+
MEDIUM 6.8
CVE-2022-46408
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper…
Network Manager
22.1+
MEDIUM 6.5
CVE-2021-28488
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were…
Network Manager
21.2+
MEDIUM 6.1
CVE-2021-44217
In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remo…
Codechecker
after 6.18.0
HIGH 8.8
CVE-2021-43339EPSS 10%
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functiona…
Network Location
2021-07-31+
MEDIUM 6.1
CVE-2021-32569
In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem…
Operations Support System Radio And Core Firmware
after 18b
HIGH 8.0
CVE-2021-41390
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.
Enterprise Content Management
No fix yet