Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Packet Core Controller MEDIUM 6.5
CVE-2025-59174

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted me…

Fix: 1.39+
Fix from $1,600 2026-06-05
Packet Core Gateway MEDIUM 6.5
CVE-2026-25659

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker co…

Fix: 1.30+
Fix from $1,600 2026-06-05
Packet Core Gateway MEDIUM 6.5
CVE-2026-25657

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability whe…

Fix: 1.30+
Fix from $1,600 2026-06-05
Packet Core Gateway MEDIUM 6.5
CVE-2026-25658

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker co…

Fix: 1.30+
Fix from $1,600 2026-06-05
Codechecker CRITICAL 9.8
CVE-2026-25660

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs …

Fix: 6.27.4+
Fix from $2,300 2026-04-24
Packet Core Controller MEDIUM 5.3
CVE-2024-53828

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted me…

Fix: after 1.38
Fix from $1,600 2026-04-01
Indoor Connect 8855 Firmware HIGH 7.5
CVE-2025-27260

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead…

Fix: 2025.q3+
Fix from $1,950 2026-03-25
Indoor Connect 8855 Firmware MEDIUM 6.1
CVE-2025-40842

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthori…

Fix: 2025.q3+
Fix from $1,600 2026-03-25
Codechecker HIGH 7.8
CVE-2025-40843

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up t…

Fix: 6.26.2+
Fix from $1,950 2025-10-28
Network Manager CRITICAL 9.8
CVE-2025-27258

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

Fix: 25.1+
Fix from $2,300 2025-10-13
Network Manager MEDIUM 5.4
CVE-2025-27259

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to…

Fix: 25.2+
Fix from $1,600 2025-10-13
Indoor Connect 8855 Firmware CRITICAL 9.8
CVE-2025-40836

Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with es…

Fix: 2025.q2+
Fix from $2,300 2025-09-25
Indoor Connect 8855 Firmware HIGH 8.8
CVE-2025-40837

Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher p…

Fix: 2025.q2+
Fix from $1,950 2025-09-25
Indoor Connect 8855 Firmware HIGH 7.5
CVE-2025-40838

Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unautho…

Fix: 2025.q2+
Fix from $1,950 2025-09-25
Indoor Connect 8855 Firmware HIGH 7.8
CVE-2025-27262

Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

Fix: 2025.q2+
Fix from $1,950 2025-09-25
Indoor Connect 8855 Firmware CRITICAL 9.8
CVE-2025-27261

Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.

Fix: 2025.q2+
Fix from $2,300 2025-09-25
Codechecker MEDIUM 6.1
CVE-2025-1300

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server c…

Fix: 6.24.6+
Fix from $1,600 2025-02-28
Codechecker HIGH 8.2
CVE-2024-53829

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery al…

Fix: 6.24.5+
Fix from $1,950 2025-01-21
Codechecker CRITICAL 10.0
CVE-2024-10081EPSS 39%

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs …

Fix: 6.24.2+
Fix from $2,300 2024-11-06
Codechecker CRITICAL 9.0
CVE-2024-10082

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusi…

Fix: 6.24.2+
Fix from $2,300 2024-11-06
Codechecker MEDIUM 6.5
CVE-2023-49793

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the serv…

Fix: 6.23.0+
Fix from $1,600 2024-06-24
Network Manager HIGH 7.1
CVE-2024-25007

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralizat…

Fix: 23.1+
Fix from $1,950 2024-04-04
Network Manager HIGH 8.8
CVE-2023-39909

Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

Fix: 23.2+
Fix from $1,950 2023-12-07
Evolved Packet Gateway HIGH 8.8
CVE-2022-47531

An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass s…

Fix: 2.16 / 3.25+
Fix from $1,950 2023-12-05
Network Manager MEDIUM 6.8
CVE-2022-46408

Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper…

Fix: 22.1+
Fix from $1,600 2023-06-29
Network Manager MEDIUM 6.5
CVE-2021-28488

Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were…

Fix: 21.2+
Fix from $1,600 2022-03-10
Codechecker MEDIUM 6.1
CVE-2021-44217

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remo…

Fix: after 6.18.0
Fix from $1,600 2022-01-18
Network Location HIGH 8.8
CVE-2021-43339EPSS 10%

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functiona…

Fix: 2021-07-31+
Fix from $1,950 2021-11-03
Operations Support System Radio And Core Firmware MEDIUM 6.1
CVE-2021-32569

In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem…

Fix: after 18b
Fix from $1,600 2021-10-14
Enterprise Content Management HIGH 8.0
CVE-2021-41390

In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

No fix yet
Fix from $1,950 2021-09-17