Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Esmpro Manager CRITICAL 9.8
CVE-2020-10917EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not requ…

Mitigation only
Fix from $2,300 2020-07-22
Aterm Wg2600hs Firmware HIGH 8.8
CVE-2020-5524

Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier…

Fix: after 1.3.2
Fix from $1,950 2020-02-21
Aterm Wg2600hs Firmware HIGH 8.0
CVE-2020-5525

Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier…

Fix: after 1.3.2
Fix from $1,950 2020-02-21
Aterm Wg2600hs Firmware HIGH 8.0
CVE-2020-5534

Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root …

Fix: after 1.3.2
Fix from $1,950 2020-02-21
Aterm Wg2600hs Firmware MEDIUM 6.1
CVE-2020-5533

Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via…

Fix: after 1.3.2
Fix from $1,600 2020-02-21
Aterm Wf1200cr Firmware HIGH 8.8
CVE-2018-16195

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on …

Fix: after 1.1.1
Fix from $1,950 2019-01-09
Aterm Wf1200cr Firmware HIGH 7.2
CVE-2018-16194

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated a…

Fix: after 1.1.1
Fix from $1,950 2019-01-09
Aterm Wf1200cr Firmware MEDIUM 6.5
CVE-2018-16192

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on t…

Fix: after 1.1.1
Fix from $1,600 2019-01-09
Aterm Wf1200cr Firmware MEDIUM 5.4
CVE-2018-16193

Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0…

Fix: after 1.1.1
Fix from $1,600 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0638

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0639

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, …

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0640

Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date para…

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0641

Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date p…

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0625

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0626

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parame…

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0627

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm Wg1200hp Firmware HIGH 7.2
CVE-2018-0628

Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and respons…

Fix: after 1.0.31
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0629

Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0630

Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0631

Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0632

Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via HTTP request and respons…

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm W300p Firmware HIGH 7.2
CVE-2018-0633

Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.

Fix: after 1.0.13
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0634

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmo…

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0635

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0636

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a cert…

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Aterm Hc100rc Firmware HIGH 7.2
CVE-2018-0637

Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.

Fix: after 1.0.1
Fix from $1,950 2019-01-09
Univerge Sv9100 Webpro Firmware CRITICAL 9.8
CVE-2018-11741EPSS 18%

NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GO…

No fix yet
Fix from $2,300 2018-12-26
Univerge Sv9100 Webpro Firmware CRITICAL 9.8
CVE-2018-11742EPSS 14%

NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

No fix yet
Fix from $2,300 2018-12-26
Expresscluster X HIGH 7.5
CVE-2016-1145

Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris all…

Mitigation only
Fix from $1,950 2016-01-30
Ip38x 1000 MEDIUM 6.8
CVE-2013-7314

The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link …

Mitigation only
Fix from $1,600 2014-01-23