Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.3
CVE-2025-27851
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU …
Empirbus Wireless Display Unit Firmware
Mitigation only
HIGH 7.5
CVE-2025-27850
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is u…
Empirbus Wireless Display Unit Firmware
Mitigation only
HIGH 7.3
CVE-2025-27853
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authenti…
Empirbus Wireless Display Unit Firmware
Mitigation only
MEDIUM 5.0
CVE-2025-27852
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on …
Empirbus Wireless Display Unit Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-23298
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result …
Connect Iq
after 4.1.7
CRITICAL 9.8
CVE-2023-23300
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in b…
Connect Iq
after 4.1.7
CRITICAL 9.8
CVE-2023-23301
The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the e…
Connect Iq
after 4.1.7
CRITICAL 9.8
CVE-2023-23302
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in bu…
Connect Iq
after 4.1.7
CRITICAL 9.8
CVE-2023-23303
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result …
Connect Iq
after 4.1.7
CRITICAL 9.8
CVE-2023-23305
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A maliciou…
Connect Iq
after 4.1.7
CRITICAL 9.8
CVE-2023-23306
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in …
Connect Iq
after 4.1.7
CRITICAL 9.1
CVE-2023-23304
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.Sensor…
Connect Iq
after 4.1.7
HIGH 7.5
CVE-2023-23299
The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malic…
Connect Iq
after 4.1.7
HIGH 7.5
CVE-2022-46081
In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal information. N…
Connect
No fix yet
CRITICAL 9.9
CVE-2020-27483
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerabil…
Forerunner 235 Firmware
8.20+
CRITICAL 9.9
CVE-2020-27484
Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerabili…
Forerunner 235 Firmware
8.20+
CRITICAL 9.9
CVE-2020-27485
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerabil…
Forerunner 235 Firmware
8.20+
CRITICAL 9.9
CVE-2020-27486
Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerabilit…
Forerunner 235 Firmware
8.20+
HIGH 9.3
CVE-2009-0194
The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4…
Garmin Communicator Plugin
Mitigation only