Vulnerability index

Browse CVEs

83 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Infinera Dna MEDIUM 6.3
CVE-2025-10258

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive…

Mitigation only
Fix from $1,600 2026-02-05
Wavesuite Noc CRITICAL 9.0
CVE-2025-24937

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full …

Mitigation only
Fix from $2,300 2025-07-21
Wavesuite Noc HIGH 8.4
CVE-2025-24938

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged a…

Mitigation only
Fix from $1,950 2025-07-21
Wavesuite Noc CRITICAL 9.0
CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound …

No fix yet
Fix from $2,300 2025-07-21
Transcend Network Management System CRITICAL 9.0
CVE-2024-25660

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized fil…

Mitigation only
Fix from $2,300 2024-10-01
Transcend Network Management System HIGH 7.2
CVE-2024-25659

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows…

Mitigation only
Fix from $1,950 2024-10-01
Transcend Network Management System HIGH 7.7
CVE-2024-25661

In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS …

Mitigation only
Fix from $1,950 2024-10-01
Transcend Network Management System MEDIUM 6.5
CVE-2024-25658

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or…

Mitigation only
Fix from $1,600 2024-10-01
Hit 7300 Firmware MEDIUM 6.5
CVE-2024-28807

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management applicat…

Mitigation only
Fix from $1,600 2024-09-30
Hit 7300 Firmware HIGH 8.8
CVE-2024-28812

An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials all…

Mitigation only
Fix from $1,950 2024-09-30
Hit 7300 Firmware HIGH 8.4
CVE-2024-28813

An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activa…

Mitigation only
Fix from $1,950 2024-09-30
Hit 7300 Firmware MEDIUM 6.6
CVE-2024-28810

An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attac…

Mitigation only
Fix from $1,600 2024-09-30
Hit 7300 Firmware HIGH 8.8
CVE-2024-28809

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access …

Mitigation only
Fix from $1,950 2024-09-30
Network Functions Manager For Transport HIGH 8.8
CVE-2022-39822

In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET paramete…

No fix yet
Fix from $1,950 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-39820

In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-41760

An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the fi…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-41761

An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.1
CVE-2022-41762

An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.1
CVE-2022-43675

An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filena…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport HIGH 8.8
CVE-2022-39818

In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. T…

No fix yet
Fix from $1,950 2023-12-25
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41351

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentic…

Mitigation only
Fix from $2,300 2023-11-03
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41355

Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attac…

Mitigation only
Fix from $2,300 2023-11-03
G 040w Q Firmware HIGH 8.8
CVE-2023-41353

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the…

Mitigation only
Fix from $1,950 2023-11-03
G 040w Q Firmware HIGH 7.2
CVE-2023-41352

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can expl…

Mitigation only
Fix from $1,950 2023-11-03
G 040w Q Firmware MEDIUM 5.3
CVE-2023-41354

Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit t…

Mitigation only
Fix from $1,600 2023-11-03
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41350

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated r…

Mitigation only
Fix from $2,300 2023-11-03
Wavelite Metro 200 And Fan Firmware HIGH 7.8
CVE-2023-22618

If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privilege…

Mitigation only
Fix from $1,950 2023-10-04
Access Management System HIGH 8.8
CVE-2022-41763

An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to…

No fix yet
Fix from $1,950 2023-09-05
Service Router Linux HIGH 7.5
CVE-2023-41376

Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attri…

No fix yet
Fix from $1,950 2023-08-29
Netact HIGH 8.8
CVE-2022-28863

An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitraril…

No fix yet
Fix from $1,950 2023-07-24