Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2025-11192
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically…
Fabric Engine \(voss\)
9.3+
CRITICAL 9.8
CVE-2025-8679
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest …
Extremeguest Essentials
25.5.0+
MEDIUM 6.1
CVE-2025-6235
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The iss…
Extremecontrol
25.5.12+
CRITICAL 9.8
CVE-2024-38292
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalatio…
Xiq Se
24.2.11+
HIGH 8.8
CVE-2024-38291
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.
Xiq Se
24.2.11+
MEDIUM 5.3
CVE-2024-38290
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
Xiq Se
24.2.11+
HIGH 8.0
CVE-2020-18305
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing …
Extremexos
22.7+
HIGH 8.6
CVE-2024-27453
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine…
Extremexos
22.7+
CRITICAL 9.8
CVE-2023-43119
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca…
Exos
22.7 / 31.7.2+
HIGH 8.8
CVE-2023-43118
Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 3…
Exos
31.7.2 / 32.5.1.5+
HIGH 7.5
CVE-2023-43121
A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and befor…
Exos
22.7 / 31.7.2+
HIGH 8.8
CVE-2023-43120
An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privil…
Exos
22.7 / 31.7.1+
CRITICAL 9.8
CVE-2023-35803
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
Iq Engine
10.6r2 / 10.6r5+
CRITICAL 9.8
CVE-2023-35802
IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obt…
Iq Engine
10.6r1 / 10.6r5+
CRITICAL 9.8
CVE-2020-16152EPSS 35%
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execu…
Aerohive Netconfig
10.0r8a+
MEDIUM 6.1
CVE-2020-13819
Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
Extreme Management Center
8.5.0.169+
MEDIUM 6.1
CVE-2020-16847
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
Extreme Management Center
8.5.0.169+
MEDIUM 6.1
CVE-2020-13820
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
Extreme Management Center
Mitigation only
HIGH 7.5
CVE-2018-5787
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Stac…
Extremewireless Wing
5.8.6.9 / 5.9.1.3+
HIGH 7.5
CVE-2018-5797
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES…
Extremewireless Wing
5.8.6.9 / 5.9.1.3+
HIGH 8.1
CVE-2017-14332
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.
Extremexos
Mitigation only
HIGH 7.5
CVE-2017-14328
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.
Extremexos
Mitigation only
MEDIUM 6.7
CVE-2017-14329
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.
Extremexos
Mitigation only
MEDIUM 6.7
CVE-2017-14330
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.
Extremexos
No fix yet
MEDIUM 6.7
CVE-2017-14331
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.
Extremexos
Mitigation only
MEDIUM 5.4
CVE-2013-7309
The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA…
Exos
Mitigation only