Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iot Edge Linux Docker CRITICAL 9.8
CVE-2025-52694EPSS 38%

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vu…

Fix: 2.0.2 / 3.4.15+
Fix from $2,300 2026-01-12
Webaccess\/scada HIGH 7.5
CVE-2025-67653

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Mitigation only
Fix from $1,950 2025-12-18
Webaccess\/scada HIGH 8.8
CVE-2025-46268

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

Mitigation only
Fix from $1,950 2025-12-18
Webaccess\/scada CRITICAL 9.8
CVE-2025-14849

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Mitigation only
Fix from $2,300 2025-12-18
Webaccess\/scada CRITICAL 9.1
CVE-2025-14850

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

Mitigation only
Fix from $2,300 2025-12-18
Webaccess\/scada MEDIUM 5.3
CVE-2025-14848

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Mitigation only
Fix from $1,600 2025-12-18
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34263

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboard…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34264

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint.…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34265

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. …

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34266

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/me…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server CRITICAL 9.8
CVE-2025-34256

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secre…

Fix: 5.4+
Fix from $2,300 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34257

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34258

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34259

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endp…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34260

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoin…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34261

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint.…

Fix: 5.4+
Fix from $1,600 2025-12-05
Wise Deviceon Server MEDIUM 5.4
CVE-2025-34262

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id}…

Fix: 5.4+
Fix from $1,600 2025-12-05
Tp 3250 Firmware MEDIUM 6.8
CVE-2025-63701

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW()…

No fix yet
Fix from $1,600 2025-11-14
Deviceon\/iedge MEDIUM 5.4
CVE-2025-64302

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or da…

Fix: after 2.0.2
Fix from $1,600 2025-11-06
Deviceon\/iedge CRITICAL 9.8
CVE-2025-59171

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code exe…

Fix: after 2.0.2
Fix from $2,300 2025-11-06
Deviceon\/iedge CRITICAL 9.8
CVE-2025-62630

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code exe…

Fix: after 2.0.2
Fix from $2,300 2025-11-06
Deviceon\/iedge HIGH 8.8
CVE-2025-58423

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse di…

Fix: after 2.0.2
Fix from $1,950 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34247

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authent…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34241

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authe…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34242

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authentica…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34243

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34244

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows …

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34245

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows …

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34246

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an auth…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn HIGH 7.2
CVE-2025-34239

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows a…

Fix: 1.1.5+
Fix from $1,950 2025-11-06