Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mantaray Nm HIGH 7.8
CVE-2025-7406

Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privilege…

Fix: 25R2-NM+
Fix from $1,950 2026-06-30
Mantaray Nm MEDIUM 6.5
CVE-2025-24816

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could…

Fix: 25R2-NM+
Fix from $1,600 2026-06-30
Mantaray Nm HIGH 7.8
CVE-2025-24815

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could all…

Fix: 25R2-NM+
Fix from $1,950 2026-06-30
Broadcast Message Center MEDIUM 6.5
CVE-2022-45899

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacter…

Fix: 13.1+
Fix from $1,600 2026-05-08
Mantaray Nm HIGH 8.0
CVE-2025-24817

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in …

Fix: 25r1-nm+
Fix from $1,950 2026-04-07
Mantaray Nm HIGH 8.0
CVE-2025-24818

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in …

Fix: 25r1-nm+
Fix from $1,950 2026-04-07
Mantaray Nm MEDIUM 5.7
CVE-2025-24819

Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Softwa…

Fix: 25r1-nm+
Fix from $1,600 2026-04-07
Impact Mobile HIGH 8.8
CVE-2023-31044

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functio…

Fix: after 23
Fix from $1,950 2026-03-03
Impact Mobile HIGH 8.1
CVE-2021-35486

A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwri…

Fix: after 19.11.2.10-20210118042150283
Fix from $1,950 2026-03-03
Impact HIGH 8.2
CVE-2021-35484

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endp…

Fix: after 19.11.2.10-20210118042150283
Fix from $1,950 2026-03-03
Impact HIGH 8.0
CVE-2021-35485

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-sid…

Fix: after 19.11.2.10-20210118042150283
Fix from $1,950 2026-03-03
Infinera Dna MEDIUM 6.3
CVE-2025-10258

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive…

Mitigation only
Fix from $1,600 2026-02-05
Infinera Mtc 9 Firmware CRITICAL 9.8
CVE-2025-27019

Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system acces…

Fix: 23.0+
Fix from $2,300 2025-12-08
Infinera Mtc 9 Firmware CRITICAL 9.8
CVE-2025-27020

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file …

Fix: 23.0+
Fix from $2,300 2025-12-08
Infinera Mtc 9 Firmware HIGH 8.6
CVE-2025-26487

Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resou…

Fix: 23.0+
Fix from $1,950 2025-12-08
Infinera Mtc 9 Firmware HIGH 7.5
CVE-2025-26488

Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the applian…

Fix: 23.0+
Fix from $1,950 2025-12-08
Infinera Mtc 9 Firmware MEDIUM 6.5
CVE-2025-26489

Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, …

Fix: 23.0+
Fix from $1,600 2025-12-08
Wavesuite Noc CRITICAL 9.0
CVE-2025-24937

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full …

Mitigation only
Fix from $2,300 2025-07-21
Wavesuite Noc HIGH 8.4
CVE-2025-24938

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged a…

Mitigation only
Fix from $1,950 2025-07-21
Wavesuite Noc CRITICAL 9.0
CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound …

No fix yet
Fix from $2,300 2025-07-21
G42 Firmware MEDIUM 6.5
CVE-2025-27023

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via cr…

Fix: 7.1+
Fix from $1,600 2025-07-02
G42 Firmware MEDIUM 6.5
CVE-2025-27024

Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via S…

Fix: 8.0+
Fix from $1,600 2025-07-02
G42 Firmware HIGH 7.8
CVE-2025-27021

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/wri…

Fix: 7.1+
Fix from $1,950 2025-07-02
G42 Firmware MEDIUM 6.5
CVE-2025-27022

A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files…

Fix: 7.1+
Fix from $1,600 2025-07-02
Transcend Network Management System CRITICAL 9.0
CVE-2024-25660

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized fil…

Mitigation only
Fix from $2,300 2024-10-01
Transcend Network Management System HIGH 7.2
CVE-2024-25659

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows…

Mitigation only
Fix from $1,950 2024-10-01
Transcend Network Management System HIGH 7.7
CVE-2024-25661

In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS …

Mitigation only
Fix from $1,950 2024-10-01
Transcend Network Management System MEDIUM 6.5
CVE-2024-25658

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or…

Mitigation only
Fix from $1,600 2024-10-01
Hit 7300 Firmware MEDIUM 6.5
CVE-2024-28807

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management applicat…

Mitigation only
Fix from $1,600 2024-09-30
Hit 7300 Firmware HIGH 8.8
CVE-2024-28812

An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials all…

Mitigation only
Fix from $1,950 2024-09-30