Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-7406 Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privilege… Mantaray Nm 25R2-NM+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2025-24816 Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could… Mantaray Nm 25R2-NM+ Fix from $1,6002026-06-30 HIGH 7.8 CVE-2025-24815 Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could all… Mantaray Nm 25R2-NM+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2022-45899 Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacter… Broadcast Message Center 13.1+ Fix from $1,6002026-05-08 HIGH 8.0 CVE-2025-24817 Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in … Mantaray Nm 25r1-nm+ Fix from $1,9502026-04-07 HIGH 8.0 CVE-2025-24818 Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in … Mantaray Nm 25r1-nm+ Fix from $1,9502026-04-07 MEDIUM 5.7 CVE-2025-24819 Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Softwa… Mantaray Nm 25r1-nm+ Fix from $1,6002026-04-07 HIGH 8.8 CVE-2023-31044 An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functio… Impact Mobile after 23 Fix from $1,9502026-03-03 HIGH 8.1 CVE-2021-35486 A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwri… Impact Mobile after 19.11.2.10-20210118042150283 Fix from $1,9502026-03-03 HIGH 8.2 CVE-2021-35484 Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endp… Impact after 19.11.2.10-20210118042150283 Fix from $1,9502026-03-03 HIGH 8.0 CVE-2021-35485 The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-sid… Impact after 19.11.2.10-20210118042150283 Fix from $1,9502026-03-03 MEDIUM 6.3 CVE-2025-10258 Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive… Infinera Dna Mitigation only Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2025-27019 Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system acces… Infinera Mtc 9 Firmware 23.0+ Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-27020 Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file … Infinera Mtc 9 Firmware 23.0+ Fix from $2,3002025-12-08 HIGH 8.6 CVE-2025-26487 Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resou… Infinera Mtc 9 Firmware 23.0+ Fix from $1,9502025-12-08 HIGH 7.5 CVE-2025-26488 Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the applian… Infinera Mtc 9 Firmware 23.0+ Fix from $1,9502025-12-08 MEDIUM 6.5 CVE-2025-26489 Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, … Infinera Mtc 9 Firmware 23.0+ Fix from $1,6002025-12-08 CRITICAL 9.0 CVE-2025-24937 File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full … Wavesuite Noc Mitigation only Fix from $2,3002025-07-21 HIGH 8.4 CVE-2025-24938 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged a… Wavesuite Noc Mitigation only Fix from $1,9502025-07-21 CRITICAL 9.0 CVE-2025-24936 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound … Wavesuite Noc No fix yet Fix from $2,3002025-07-21 MEDIUM 6.5 CVE-2025-27023 Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via cr… G42 Firmware 7.1+ Fix from $1,6002025-07-02 MEDIUM 6.5 CVE-2025-27024 Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via S… G42 Firmware 8.0+ Fix from $1,6002025-07-02 HIGH 7.8 CVE-2025-27021 The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/wri… G42 Firmware 7.1+ Fix from $1,9502025-07-02 MEDIUM 6.5 CVE-2025-27022 A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files… G42 Firmware 7.1+ Fix from $1,6002025-07-02 CRITICAL 9.0 CVE-2024-25660 The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized fil… Transcend Network Management System Mitigation only Fix from $2,3002024-10-01 HIGH 7.2 CVE-2024-25659 In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows… Transcend Network Management System Mitigation only Fix from $1,9502024-10-01 HIGH 7.7 CVE-2024-25661 In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS … Transcend Network Management System Mitigation only Fix from $1,9502024-10-01 MEDIUM 6.5 CVE-2024-25658 Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or… Transcend Network Management System Mitigation only Fix from $1,6002024-10-01 MEDIUM 6.5 CVE-2024-28807 An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management applicat… Hit 7300 Firmware Mitigation only Fix from $1,6002024-09-30 HIGH 8.8 CVE-2024-28812 An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials all… Hit 7300 Firmware Mitigation only Fix from $1,9502024-09-30