Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.4
CVE-2024-28813
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activa…
Hit 7300 Firmware
Mitigation only
MEDIUM 6.6
CVE-2024-28810
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attac…
Hit 7300 Firmware
Mitigation only
HIGH 8.8
CVE-2024-28809
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access …
Hit 7300 Firmware
Mitigation only
HIGH 8.8
CVE-2022-39822
In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET paramete…
Network Functions Manager For Transport
No fix yet
MEDIUM 6.5
CVE-2022-39820
In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and…
Network Functions Manager For Transport
No fix yet
MEDIUM 6.5
CVE-2022-41760
An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the fi…
Network Functions Manager For Transport
No fix yet
MEDIUM 6.5
CVE-2022-41761
An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI…
Network Functions Manager For Transport
No fix yet
MEDIUM 6.1
CVE-2022-41762
An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl…
Network Functions Manager For Transport
No fix yet
MEDIUM 6.1
CVE-2022-43675
An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filena…
Network Functions Manager For Transport
No fix yet
HIGH 8.8
CVE-2022-39818
In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. T…
Network Functions Manager For Transport
No fix yet
CRITICAL 9.8
CVE-2023-41351
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentic…
G 040w Q Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-41355
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attac…
G 040w Q Firmware
Mitigation only
HIGH 8.8
CVE-2023-41353
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the…
G 040w Q Firmware
Mitigation only
HIGH 7.2
CVE-2023-41352
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can expl…
G 040w Q Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-41354
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit t…
G 040w Q Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-41350
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated r…
G 040w Q Firmware
Mitigation only
HIGH 7.8
CVE-2023-22618
If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privilege…
Wavelite Metro 200 And Fan Firmware
Mitigation only
HIGH 8.8
CVE-2022-41763
An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to…
Access Management System
No fix yet
HIGH 7.5
CVE-2023-41376
Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attri…
Service Router Linux
No fix yet
HIGH 8.8
CVE-2022-28863
An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitraril…
Netact
No fix yet
HIGH 8.8
CVE-2022-28864
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateN…
Netact
No fix yet
HIGH 8.8
CVE-2022-30280
/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even adm…
Netact
No fix yet
MEDIUM 5.4
CVE-2022-28865
An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded…
Netact
No fix yet
MEDIUM 5.4
CVE-2022-28867
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateN…
Netact
No fix yet
HIGH 7.0
CVE-2023-25187
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time …
Asika Airscale Firmware
No fix yet
HIGH 7.8
CVE-2023-25185
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN…
Asika Airscale Firmware
Mitigation only
HIGH 7.8
CVE-2023-25188
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from …
Asika Airscale Firmware
Mitigation only
HIGH 7.8
CVE-2023-26062
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute…
Web Element Manager
22r1+
HIGH 8.8
CVE-2022-30759
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and…
One Nds
after 20.9
HIGH 7.8
CVE-2022-31244
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
One Network Directory Server
No fix yet