|
cve-2025-2777
|
CVE-2025-2777 |
CRITICAL
|
9.3
|
72.20%
|
cvelistv5 |
|
|
cve-2025-2776
|
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability |
CRITICAL
|
9.3
|
64.40%
|
cvelistv5 |
2025-07-22 |
|
cve-2025-2775
|
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability |
CRITICAL
|
9.3
|
42.95%
|
cvelistv5 |
2025-07-22 |
|
cve-2025-26793
|
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password." |
CRITICAL
|
9.3
|
2.40%
|
cvelistv5 |
2026-06-17 |
|
cve-2024-29972
|
CVE-2024-29972 |
CRITICAL
|
9.8
|
89.33%
|
cvelistv5 |
|
|
cve-2023-43177
|
CVE-2023-43177 |
HIGH
|
N/A
|
81.80%
|
cvelistv5 |
|
|
cve-2023-0656
|
CVE-2023-0656 |
HIGH
|
N/A
|
41.32%
|
cvelistv5 |
|
|
cve-2022-4257
|
CVE-2022-4257 |
MEDIUM
|
6.3
|
43.93%
|
cvelistv5 |
|
|
cve-2022-22274
|
CVE-2022-22274 |
HIGH
|
N/A
|
75.52%
|
cvelistv5 |
|
|
cve-2020-9377
|
D-Link DIR-610 Devices Remote Command Execution |
HIGH
|
8.8
|
21.34%
|
cvelistv5 |
2022-03-25 |
|
cve-2020-2507
|
CVE-2020-2507 |
CRITICAL
|
9.8
|
3.04%
|
cvelistv5 |
|
|
cve-2017-11610
|
supervisor: Command injection via malicious XML-RPC request |
HIGH
|
7.0
|
87.38%
|
cvelistv5 |
2026-05-13 |
|
cve-2026-58644
|
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
HIGH
|
N/A
|
15.87%
|
cvelistv5 |
2026-07-16 |
|
cve-2026-39808
|
Fortinet FortiSandbox OS Command Injection Vulnerability |
HIGH
|
N/A
|
47.36%
|
cvelistv5 |
2026-07-16 |
|
cve-2026-25089
|
Fortinet FortiSandbox OS Command Injection Vulnerability |
CRITICAL
|
9.1
|
76.11%
|
cvelistv5 |
2026-07-16 |
|
cve-2023-4346
|
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability |
HIGH
|
N/A
|
1.29%
|
cvelistv5 |
2026-07-15 |
|
cve-2026-1281
|
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability |
HIGH
|
N/A
|
98.58%
|
cvelistv5 |
2026-01-29 |
|
cve-2025-53770
|
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
CRITICAL
|
9.8
|
100.00%
|
cvelistv5 |
2025-07-20 |
|
cve-2023-3519
|
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability |
CRITICAL
|
9.8
|
99.75%
|
cvelistv5 |
2023-07-19 |
|
cve-2022-36553
|
CVE-2022-36553 |
HIGH
|
N/A
|
90.90%
|
cvelistv5 |
|
|
cve-2021-22205
|
SUSE CVE CVE-2021-22205 |
UNKNOWN
|
N/A
|
99.73%
|
cvelistv5 |
2025-02-17 |
|
cve-2017-8226
|
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro, one will notice that this follows a ARM little endian format. The function sub_3DB2FC in IDA pro is identified to be setting up the values at address 0x003DB5A6. The sub_5C057C then sets this value and adds it to the Configuration files in /mnt/mtd/Config/Account1 file. |
CRITICAL
|
9.8
|
3.80%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-12149
|
Red Hat JBoss Application Server Remote Code Execution Vulnerability |
CRITICAL
|
N/A
|
90.71%
|
cvelistv5 |
2021-12-10 |
|
cve-2013-2678
|
CVE-2013-2678 |
HIGH
|
N/A
|
16.87%
|
cvelistv5 |
|
|
cve-2026-46817
|
Oracle E-Business Suite Improper Privilege Management Vulnerability |
HIGH
|
N/A
|
0.81%
|
cvelistv5 |
2026-07-15 |
|
cve-2023-4346
|
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability |
HIGH
|
N/A
|
1.29%
|
cvelistv5 |
2026-07-15 |
|
cve-2026-15410
|
SonicWall SMA1000 Appliances Code Injection Vulnerability |
HIGH
|
7.2
|
11.79%
|
cvelistv5 |
2026-07-14 |
|
cve-2026-15409
|
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability |
CRITICAL
|
N/A
|
6.79%
|
cvelistv5 |
2026-07-14 |
|
cve-2026-56164
|
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability |
HIGH
|
N/A
|
1.01%
|
cvelistv5 |
2026-07-14 |
|
cve-2026-56155
|
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability |
HIGH
|
7.8
|
0.35%
|
cvelistv5 |
2026-07-14 |