Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · advantech

advantech

· 63 Critical

Total CVEs

378

Critical

63

Products

96

Search All CVEs →

378

Products (96)

webaccess103 CVEsadvantech webaccess44 CVEsr-seenet40 CVEsiview37 CVEswebaccess\/scada29 CVEseki-6333ac-2gd20 CVEseki-6333ac-2gd firmware20 CVEswebaccess\/nms20 CVEseki-6333ac-1gpo20 CVEseki-6333ac-1gpo firmware20 CVEseki-6333ac-2g20 CVEseki-6333ac-2g firmware20 CVEswebaccess\/hmi designer12 CVEswebaccess scada12 CVEswebaccess\/vpn12 CVEswise-deviceon server11 CVEswebaccess dashboard11 CVEswise-4010lan8 CVEswise-4060lan8 CVEswise-4050lan8 CVEswise-4060lan firmware8 CVEswise-4010lan firmware8 CVEswise-4050lan firmware8 CVEswebaccess hmi designer6 CVEseki-1522 firmware5 CVEseki-15245 CVEseki-1524 firmware5 CVEsdeviceon\/iedge5 CVEseki-15215 CVEseki-1521 firmware5 CVEseki-15225 CVEswise-paas\/rmm5 CVEsspectre rt ert351 firmware3 CVEsspectre rt ert3513 CVEsadvantech studio3 CVEsadam-5630 firmware3 CVEsadam-56303 CVEssusiaccess3 CVEseki-1222d2 CVEseki-12222 CVEseki-1221d2 CVEseki-1322 series firmware2 CVEsadam-55502 CVEseki-13222 CVEseki-1321 series firmware2 CVEseki-12212 CVEseki-13212 CVEseki-12242 CVEsiot edge windows1 CVEsadam-3600 firmware1 CVEsadam-5550 firmware1 CVEsadam-60151 CVEsadam-60171 CVEsadam-60181 CVEsadam-60221 CVEsadam-60241 CVEsadam-60501 CVEsadam-6050w1 CVEsadam-60511 CVEsadam-6051w1 CVEsadam-60521 CVEsadam-60601 CVEsadam-6060w1 CVEsadam-60661 CVEsadam-65011 CVEsadam 5550-firmware1 CVEsadam opc server1 CVEsadamview1 CVEsbb-eswgp506-2sfp-t1 CVEsbb-eswgp506-2sfp-t firmware1 CVEsdeviceon\/iservice1 CVEsdiaganywhere1 CVEseki-1200 gateway series firmware1 CVEseki-122x series firmware1 CVEseki-13611 CVEseki-1361 series firmware1 CVEseki-13621 CVEseki-1362 series firmware1 CVEseki-63401 CVEseki-6340 firmware1 CVEsiot edge linux docker1 CVEsadam-36001 CVEsiotsuite growth linux docker1 CVEsiotsuite saas composer1 CVEsiotsuite starter linux docker1 CVEsmodbus rtu opc server1 CVEsmodbus tcp opc server1 CVEssq manager1 CVEstp 32501 CVEstp 3250 firmware1 CVEsvesp211-2321 CVEsvesp211-232 firmware1 CVEsvesp211-eu1 CVEsvesp211-eu firmware1 CVEswebop1 CVEswise-paas\/ota1 CVEs

Recent Vulnerabilities

View all 378
CVE-2025-52694CRITICAL 10.0

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

CVE-2025-67653MEDIUM 4.3

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

CVE-2025-46268MEDIUM 6.3

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

CVE-2025-14850HIGH 8.1

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

CVE-2025-14849HIGH 8.8

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

CVE-2025-14848MEDIUM 4.3

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

CVE-2025-34266MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34265MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34264MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34263MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and later rendered in the dashboard UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected dashboard, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34262MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34261MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34260MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34259MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An attacker can inject malicious script into the map entry name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34258MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34257MEDIUM 5.4

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.

CVE-2025-34256CRITICAL 9.8

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.

CVE-2025-63701MEDIUM 6.8

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size matches the input buffer size, leading to invalid memory operations and heap corruption. This vulnerability can cause denial of service through application crashes and potentially lead to code execution in user space. Local access is required to exploit this vulnerability.

CVE-2025-64302MEDIUM 6.4

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

CVE-2025-62630HIGH 8.8

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

CVE-2025-59171HIGH 7.5

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

CVE-2025-58423HIGH 8.8

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

CVE-2025-34247MEDIUM 6.5

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

CVE-2025-34246MEDIUM 6.5

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

CVE-2025-34245MEDIUM 6.5

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.