Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-35246
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
L210 F2g Lynx Firmware
No fix yet
HIGH 7.5
CVE-2024-32943
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
L210 F2g Firmware
No fix yet
HIGH 7.5
CVE-2024-37183
Plain text credentials and session ID can be captured with a network sniffer.
L210 F2g Firmware
Mitigation only
HIGH 8.0
CVE-2023-45735
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the d…
L206 F2g Firmware
No fix yet
MEDIUM 5.4
CVE-2023-45227
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payl…
L206 F2g Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-45213
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the…
L206 F2g Firmware
No fix yet
MEDIUM 5.7
CVE-2023-40544
An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive informati…
L206 F2g Firmware
Mitigation only
MEDIUM 5.4
CVE-2023-40143
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cro…
L206 F2g Firmware
Mitigation only
MEDIUM 5.4
CVE-2023-42765
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "usernam…
L206 F2g Firmware
Mitigation only
MEDIUM 5.4
CVE-2023-45222
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site script…
L206 F2g Firmware
Mitigation only
HIGH 8.8
CVE-2023-38579
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which cou…
L206 F2g Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-7227
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the so…
Mrd 315 Firmware
No fix yet
HIGH 8.8
CVE-2018-19612
The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute…
Dr 250 Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-19613
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
Dr 260 Firmware
No fix yet
MEDIUM 6.1
CVE-2018-19614
XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
Dr 250 Firmware
Mitigation only
HIGH 8.8
CVE-2017-12703
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions …
Mrd 305 Din Firmware
Mitigation only
HIGH 7.5
CVE-2016-5816
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older t…
Mrd 305 Din Firmware
Mitigation only
MEDIUM 5.3
CVE-2017-12709
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.…
Mrd 305 Din Firmware
Mitigation only
CRITICAL 9.0
CVE-2015-7923
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle atta…
Weos
Mitigation only