Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2019-10655EPSS 15%
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau…
Gac2500 Firmware
1.0.3.51 / 1.0.3.219+
CRITICAL 9.8
CVE-2019-10661
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
Gxv3611ir Hd Firmware
1.0.3.23+
HIGH 8.8
CVE-2019-10656
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a …
Gwn7000 Firmware
1.0.6.32+
HIGH 8.8
CVE-2019-10658
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a …
Gwn7610 Firmware
1.0.8.18+
HIGH 8.8
CVE-2019-10659
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharact…
Gxv3370 Firmware
1.0.1.41 / 1.0.3.6+
HIGH 8.8
CVE-2019-10660
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/s…
Gxv3611ir Hd Firmware
1.0.3.23+
HIGH 8.8
CVE-2019-10662EPSS 44%
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConf…
Ucm6204 Firmware
1.0.19.20+
HIGH 8.8
CVE-2019-10663EPSS 28%
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodebl…
Ucm6204 Firmware
1.0.19.20+
MEDIUM 6.5
CVE-2019-10657
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply …
Gwn7610 Firmware
1.0.6.32 / 1.0.8.18+
HIGH 8.8
CVE-2017-16565
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree…
Ht802 Firmware
No fix yet
HIGH 8.0
CVE-2017-16563
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to …
Ht802 Firmware
No fix yet
MEDIUM 5.4
CVE-2017-16564
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject…
Ht802 Firmware
No fix yet
HIGH 8.1
CVE-2016-1518
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle…
Wave
after 1.0.1.26
HIGH 7.8
CVE-2016-1520
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle …
Wave
after 1.0.1.26
MEDIUM 5.9
CVE-2016-1519
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allo…
Wave
after 1.0.1.26
HIGH 7.5
CVE-2015-2866
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL c…
Gxv3611 Hd Firmware
after 1.0.3.6
MEDIUM 6.8
CVE-2013-3963
Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P…
Gxv Device Firmware
after 1.0.4.43
HIGH 7.8
CVE-2007-5789
The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060.
Ht488
Mitigation only
HIGH 7.1
CVE-2007-5788
Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP…
Ht488
Mitigation only
HIGH 7.8
CVE-2007-4498EPSS 14%
The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, …
Sip Phone
No fix yet
HIGH 7.8
CVE-2007-1590
The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cr…
Budgetone 200
Mitigation only
HIGH 7.8
CVE-2006-5231
Grandstream GXP-2000 VoIP Desktop Phone, firmware version 1.1.0.5, allows remote attackers to cause a denial of service (hang or reboot) via a large …
Gxp 2000
Patch available
MEDIUM 5.0
CVE-2005-2581
Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (devic…
Budgetone 101
after 1.0.6.7
HIGH 7.5
CVE-2005-2182
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a …
Bt 100 Firmware
Mitigation only