Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Veristand CRITICAL 9.8
CVE-2024-6794

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Success…

Fix: after 2024
Fix from $2,300 2024-07-22
Veristand CRITICAL 9.8
CVE-2024-6805

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result i…

Fix: after 2024
Fix from $2,300 2024-07-22
Veristand HIGH 7.8
CVE-2024-6791

A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exp…

Fix: after 2024
Fix from $1,950 2024-07-22
Flexlogger HIGH 7.8
CVE-2024-6121

An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects…

Fix: after 2024
Fix from $1,950 2024-07-22
Systemlink MEDIUM 5.5
CVE-2024-6122

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosu…

Fix: after 2024
Fix from $1,600 2024-07-22
Labview MEDIUM 5.5
CVE-2024-6638

An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exp…

Fix: after 2021
Fix from $1,600 2024-07-22
Labview HIGH 7.8
CVE-2024-23609

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a u…

Fix: after 2020
Fix from $1,950 2024-03-11
Labview HIGH 7.8
CVE-2024-23610

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Fix: after 2020
Fix from $1,950 2024-03-11
Labview HIGH 7.8
CVE-2024-23611

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Fix: after 2020
Fix from $1,950 2024-03-11
Labview HIGH 7.8
CVE-2024-23612

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a u…

Fix: after 2020
Fix from $1,950 2024-03-11
Labview HIGH 7.8
CVE-2024-23608

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to…

Fix: after 2020
Fix from $1,950 2024-03-11
Topografix Data Plugin MEDIUM 5.5
CVE-2023-5136

An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulne…

Mitigation only
Fix from $1,600 2023-11-08
System Configuration CRITICAL 9.8
CVE-2023-4601

A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execu…

Fix: 2023+
Fix from $2,300 2023-10-18
Measurementlink HIGH 8.8
CVE-2023-4570

An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on loca…

Fix: 1.1.1+
Fix from $1,950 2023-10-05
Labview Command Line Interface HIGH 7.8
CVE-2022-42718

Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially e…

Fix: 22.3.1+
Fix from $1,950 2022-12-01
Configuration Manager HIGH 7.8
CVE-2022-35415

An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially enable escalation of privilege…

Fix: 22.5.0+
Fix from $1,950 2022-09-16
Flexlogger MEDIUM 6.1
CVE-2022-27237

There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in …

Fix: 1.2+
Fix from $1,600 2022-04-21
Ni Service Locator HIGH 7.8
CVE-2021-42563

There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user …

Fix: 18.0.0.49152+
Fix from $1,950 2021-11-12
Ni Pal HIGH 7.8
CVE-2021-38304

Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable es…

Fix: after 20.0.0
Fix from $1,950 2021-09-17
Compactrio Firmware HIGH 7.5
CVE-2020-25191

Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that c…

Fix: 20.5+
Fix from $1,950 2020-12-11
Labview HIGH 7.8
CVE-2017-2779

An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabV…

Patch available
Fix from $1,950 2017-09-05
Labview HIGH 7.8
CVE-2017-2775

An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabVIEW before 2015 SP1 f7 Patch …

No fix yet
Fix from $1,950 2017-03-31
Labview HIGH 10.0
CVE-2013-5022

Absolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, La…

Fix: after 2013
Fix from $1,950 2013-08-06
Labview HIGH 9.3
CVE-2013-5021

Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlie…

Fix: after 2013
Fix from $1,950 2013-08-06
Lookout HIGH 9.3
CVE-2013-5026

An ActiveX control in lookout650.ocx, lookout660.ocx, and lookout670.ocx in National Instruments Lookout 6.5 through 6.7 allows remote attackers to e…

Patch available
Fix from $1,950 2013-08-06