Vulnerability index

Browse CVEs

116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Baggage Analytics MEDIUM 5.3
CVE-2025-58586

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a n…

Mitigation only
Fix from $1,600 2025-10-06
Enterprise Analytics HIGH 7.5
CVE-2025-58582

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possi…

Mitigation only
Fix from $1,950 2025-10-06
Baggage Analytics MEDIUM 5.3
CVE-2025-58579

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for…

Mitigation only
Fix from $1,600 2025-10-06
Enterprise Analytics MEDIUM 5.3
CVE-2025-58580

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attack…

Mitigation only
Fix from $1,600 2025-10-06
Enterprise Analytics MEDIUM 5.3
CVE-2025-58583

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

Mitigation only
Fix from $1,600 2025-10-06
Field Analytics CRITICAL 9.8
CVE-2025-49199

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. Th…

Mitigation only
Fix from $2,300 2025-06-12
Media Server HIGH 7.5
CVE-2025-49198

The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing …

Mitigation only
Fix from $1,950 2025-06-12
Field Analytics HIGH 7.5
CVE-2025-49200

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the …

Mitigation only
Fix from $1,950 2025-06-12
Media Server CRITICAL 9.8
CVE-2025-49195

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compro…

Mitigation only
Fix from $2,300 2025-06-12
Field Analytics CRITICAL 9.1
CVE-2025-49196

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected…

Mitigation only
Fix from $2,300 2025-06-12
Media Server HIGH 7.5
CVE-2025-49194

The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept tra…

Mitigation only
Fix from $1,950 2025-06-12
Media Server HIGH 7.5
CVE-2025-49197

The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.

Fix: 1.5+
Fix from $1,950 2025-06-12
Field Analytics MEDIUM 6.1
CVE-2025-49192

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into cli…

Fix: 1.5+
Fix from $1,600 2025-06-12
Baggage Analytics MEDIUM 6.1
CVE-2025-49193

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., p…

Fix: 1.5+
Fix from $1,600 2025-06-12
Field Analytics HIGH 7.5
CVE-2025-49188

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

Mitigation only
Fix from $1,950 2025-06-12
Media Server MEDIUM 6.1
CVE-2025-49189

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting th…

Fix: 1.5+
Fix from $1,600 2025-06-12
Field Analytics MEDIUM 6.1
CVE-2025-49191

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it…

Mitigation only
Fix from $1,600 2025-06-12
Field Analytics MEDIUM 5.8
CVE-2025-49190

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

Mitigation only
Fix from $1,600 2025-06-12
Field Analytics MEDIUM 5.3
CVE-2025-49187

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a n…

Mitigation only
Fix from $1,600 2025-06-12
Media Server CRITICAL 9.8
CVE-2025-49182

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full acces…

Fix: 1.5+
Fix from $2,300 2025-06-12
Media Server HIGH 8.6
CVE-2025-49181

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could als…

Mitigation only
Fix from $1,950 2025-06-12
Media Server HIGH 7.5
CVE-2025-49183

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads t…

Mitigation only
Fix from $1,950 2025-06-12
Baggage Analytics HIGH 7.5
CVE-2025-49184

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the pro…

Mitigation only
Fix from $1,950 2025-06-12
Field Analytics MEDIUM 5.4
CVE-2025-49185

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript …

Mitigation only
Fix from $1,600 2025-06-12
Fx0 Gent00000 Firmware HIGH 8.8
CVE-2023-5246

Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1…

Mitigation only
Fix from $1,950 2023-10-23
Apu0200 Firmware MEDIUM 6.5
CVE-2023-43697

Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary …

Fix: 4.0.0.6+
Fix from $1,600 2023-10-09
Apu0200 Firmware MEDIUM 6.5
CVE-2023-5100

Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive inform…

Fix: 4.0.0.6+
Fix from $1,600 2023-10-09
Apu0200 Firmware MEDIUM 6.1
CVE-2023-43698

Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to …

Fix: 4.0.0.6+
Fix from $1,600 2023-10-09
Apu0200 Firmware MEDIUM 5.3
CVE-2023-5101

Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the s…

Fix: 4.0.0.6+
Fix from $1,600 2023-10-09
Apu0200 Firmware MEDIUM 5.3
CVE-2023-5102

Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP…

Fix: 4.0.0.6+
Fix from $1,600 2023-10-09