Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2025-7406
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privilege…
Mantaray Nm
25R2-NM+
MEDIUM 6.5
CVE-2025-24816
Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could…
Mantaray Nm
25R2-NM+
HIGH 7.8
CVE-2025-24815
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could all…
Mantaray Nm
25R2-NM+
MEDIUM 6.5
CVE-2022-45899
Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacter…
Broadcast Message Center
13.1+
HIGH 8.0
CVE-2025-24817
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in …
Mantaray Nm
25r1-nm+
HIGH 8.0
CVE-2025-24818
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in …
Mantaray Nm
25r1-nm+
MEDIUM 5.7
CVE-2025-24819
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Softwa…
Mantaray Nm
25r1-nm+
HIGH 8.8
CVE-2023-31044
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functio…
Impact Mobile
after 23
HIGH 8.1
CVE-2021-35486
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwri…
Impact Mobile
after 19.11.2.10-20210118042150283
HIGH 8.2
CVE-2021-35484
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endp…
Impact
after 19.11.2.10-20210118042150283
HIGH 8.0
CVE-2021-35485
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-sid…
Impact
after 19.11.2.10-20210118042150283
MEDIUM 6.3
CVE-2025-10258
Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive…
Infinera Dna
Mitigation only
CRITICAL 9.8
CVE-2025-27019
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows
an attacker to utilize password-less user accounts and obtain
system acces…
Infinera Mtc 9 Firmware
23.0+
CRITICAL 9.8
CVE-2025-27020
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file …
Infinera Mtc 9 Firmware
23.0+
HIGH 8.6
CVE-2025-26487
Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows
remote unauthenticated users to gain access to other network resou…
Infinera Mtc 9 Firmware
23.0+
HIGH 7.5
CVE-2025-26488
Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a
reboot of the applian…
Infinera Mtc 9 Firmware
23.0+
MEDIUM 6.5
CVE-2025-26489
Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and
reboot the appliance, …
Infinera Mtc 9 Firmware
23.0+
CRITICAL 9.0
CVE-2025-24937
File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full …
Wavesuite Noc
Mitigation only
HIGH 8.4
CVE-2025-24938
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged a…
Wavesuite Noc
Mitigation only
CRITICAL 9.0
CVE-2025-24936
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound …
Wavesuite Noc
No fix yet
MEDIUM 6.5
CVE-2025-27023
Lack or insufficent input validation in WebGUI CLI web in Infinera G42
version R6.1.3 allows remote authenticated users to read all OS files
via cr…
G42 Firmware
7.1+
MEDIUM 6.5
CVE-2025-27024
Unrestricted access to OS file system in SFTP service in Infinera G42
version R6.1.3 allows remote authenticated users to read/write OS files
via S…
G42 Firmware
8.0+
HIGH 7.8
CVE-2025-27021
The misconfiguration in the sudoers configuration of the operating system in
Infinera G42 version R6.1.3 allows low privileged OS users to
read/wri…
G42 Firmware
7.1+
MEDIUM 6.5
CVE-2025-27022
A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3
allows remote authenticated users to download all OS files…
G42 Firmware
7.1+
CRITICAL 9.0
CVE-2024-25660
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized fil…
Transcend Network Management System
Mitigation only
HIGH 7.2
CVE-2024-25659
In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows…
Transcend Network Management System
Mitigation only
HIGH 7.7
CVE-2024-25661
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS …
Transcend Network Management System
Mitigation only
MEDIUM 6.5
CVE-2024-25658
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or…
Transcend Network Management System
Mitigation only
MEDIUM 6.5
CVE-2024-28807
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management applicat…
Hit 7300 Firmware
Mitigation only
HIGH 8.8
CVE-2024-28812
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials all…
Hit 7300 Firmware
Mitigation only