Vulnerabilities

Summary — last 7 days

New vulnerabilities2,840▲ 88 vs. last week
Critical / high1,317▼ 206 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

70 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)0.90%—Sierrawireless Airlink Mobility Manager12/26/20226/17/2026
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
ModifiedMedium (5.4)0.61%—Auto-hyperlink Urls Project Auto-hyperlink Urls8/22/20226/17/2026
The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.
ModifiedHigh (8.8)2.6%—Podman Project PodmanVarlink6/9/20226/17/2026
A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModifiedHigh (7.8)0.87%—Cyberlink Powerdirector5/24/20227/9/2026
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
ModifiedMedium (5.4)0.62%—Wpdeveloper Betterlinks11/23/20216/17/2026
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
ModifiedHigh (7.2)6.7%💥 ExploitG Auto-hyperlink Project G Auto-hyperlink11/8/20216/17/2026
The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection
ModifiedHigh (7.1)14%—Sierrawireless Airlink Es450 Firmware10/31/20196/17/2026
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can…
ModifiedHigh (8.8)26%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endpoint /cgi-bin/Embeded_Ace_TLSet_Task.cgi is a very similar endpoint that is designed for use with setting table values that can cause an…
ModifiedHigh (8.8)26%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII configuration values within the configuration manager of the AirLink ES450. This binary does not…
ModifiedHigh (8.8)18%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_Task.cgi executable is used to retrieve MSCII configuration values within the configuration manager of the AirLink ES450. This binary does…
ModifiedHigh (8.8)18%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using…
ModifiedMedium (6.5)4.1%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a information leak, resulting in the disclosure of internal paths and files. An attacker can make an authenticated HTTP…
ModifiedHigh (8.8)1.9%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an…
ModifiedMedium (6.1)4.9%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the execution of javascript code running on the victim's browser. An…
ModifiedHigh (8.1)5.3%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration…
ModifiedHigh (7.5)4.1%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this…
ModifiedMedium (5.3)11%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.
ModifiedHigh (8.8)19%—Sierrawireless Airlink Es450 Firmware5/6/20196/17/2026
An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this…
ModifiedMedium (6.4)0.24%—Subaru Starlink 2017 FirmwareSubaru Starlink 2018 FirmwareSubaru Starlink 2019 Firmware11/28/20186/17/2026
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the vehicle's USB ports) the ability to rewrite the firmware of the head unit. This occurs because the device accepts modified QNX6 filesystem images (as long as the attacker…
ModifiedHigh (7.8)19%💥 ExploitCyberlink Labelprint9/23/20176/17/2026
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.
ModifiedHigh (8.8)17%💥 ExploitAirlink101 Skyipcam1620w Wireless N Mpeg4 3gpp Firmware7/25/20176/17/2026
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter.
ModifiedHigh (7.5)1.6%—Sierra Wireless Airlink Raven XE FirmwareSierra Wireless Airlink Raven XT Firmware6/30/20176/17/2026
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing, which could lead to information…
ModifiedCritical (9.8)4.3%—Sierra Wireless Airlink Raven XE FirmwareSierra Wireless Airlink Raven XT Firmware6/30/20176/17/2026
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including…
ModifiedHigh (8.8)0.64%—Sierra Wireless Airlink Raven XE FirmwareSierra Wireless Airlink Raven XT Firmware6/30/20176/17/2026
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an…
ModifiedMedium (5.3)1.2%—Visonic Powerlink2 Firmware2/13/20176/17/2026
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. When a specific URL to an image is accessed, the downloaded image carries with it source code used in the web server (INFORMATION EXPOSURE).
Orbitaley — Vulnerabilities