Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · nokia

nokia

· 12 Critical

Total CVEs

147

Critical

12

Products

110

Search All CVEs →

147

Products (110)

netact12 CVEs1350 optical management system10 CVEshit 73007 CVEshit 7300 firmware7 CVEsnetwork functions manager for transport7 CVEsimpact7 CVEsi-240w-q gpon ont6 CVEsi-240w-q gpon ont firmware6 CVEsg-040w-q6 CVEsg-040w-q firmware6 CVEsg425 CVEsinfinera mtc-9 firmware5 CVEsinfinera mtc-95 CVEsg42 firmware5 CVEsaffix4 CVEsasika airscale firmware4 CVEsasika airscale4 CVEstranscend network management system4 CVEsfastmile firmware3 CVEsasik airscale 474021a.101 firmware3 CVEsn953 CVEsgroupwise mobile server3 CVEsheif3 CVEsintellisync mobile suite3 CVEsintellisync wireless email express3 CVEsfastmile3 CVEs6131 nfc3 CVEsmantaray nm3 CVEsasik airscale 474021a.1013 CVEswavesuite noc3 CVEselectronic documentation3 CVEssymbian2 CVEsseries 402 CVEsimpact mobile2 CVEsn822 CVEsasik airscale 474021a.102 firmware2 CVEsasik airscale 474021a.1022 CVEsn702 CVEsggsn1 CVEsinfinera dna1 CVEsip440 firewall vpn appliance1 CVEsipso1 CVEsmultimedia player1 CVEsn81 CVEsn810 internet tablet1 CVEsnokia pc suite1 CVEsone-nds1 CVEsone-network directory server1 CVEsoro1 CVEspc suite1 CVEsqt creator1 CVEsqtdemobrowser1 CVEss601 CVEsseries1 CVEsservice router linux1 CVEsservice router operating system1 CVEssgsn dx2001 CVEssymbian s60 browser1 CVEsvertu constellation t1 CVEsvitalsuite1 CVEswavelite metro 200 and f2b fans1 CVEswavelite metro 200 and f2b fans firmware1 CVEswavelite metro 200 and fan1 CVEswavelite metro 200 and fan firmware1 CVEswavelite metro 200 ne and f2b fans1 CVEswavelite metro 200 ne and f2b fans firmware1 CVEswavelite metro 200 ne ops and f2b fans1 CVEswavelite metro 200 ne ops and f2b fans firmware1 CVEswavelite metro 200 ops and f2b fans1 CVEswavelite metro 200 ops and f2b fans firmware1 CVEswavelite metro 200 ops and fans1 CVEswavelite metro 200 ops and fans firmware1 CVEsweb element manager1 CVEs1830 photonic service switch-161 CVEs1830 photonic service switch-16 firmware1 CVEs1830 photonic service switch-321 CVEs1830 photonic service switch-32 firmware1 CVEs1830 photonic service switch-41 CVEs1830 photonic service switch-4 firmware1 CVEs32101 CVEs5001 CVEs6031 CVEs6210 handset1 CVEs6310i1 CVEs7001 CVEs7011 CVEs76101 CVEs808 pureview1 CVEs8810 4g1 CVEs8810 4g firmware1 CVEs95001 CVEs\@vantage commander1 CVEsaccess management system1 CVEsairframe bmc web gui r18 firmware1 CVEsbroadcast message center1 CVEsbts trs web console1 CVEsc6-011 CVEsc71 CVEse61 CVEse71 CVEse751 CVEse75 firmware1 CVEse90 communicator1 CVEsfastmile 5g receiver1 CVEsfastmile 5g receiver firmware1 CVEsfirewall appliance1 CVEsg-120w-f1 CVEsg-120w-f firmware1 CVEsg-2425g-a1 CVEsg-2425g-a firmware1 CVEs

Recent Vulnerabilities

View all 147
CVE-2025-24819MEDIUM 5.7

Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.

CVE-2025-24818HIGH 8.0

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.

CVE-2025-24817HIGH 8.0

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.

CVE-2023-31044LOW 2.0

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.

CVE-2021-35486HIGH 8.1

A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.

CVE-2021-35485HIGH 8.0

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.

CVE-2021-35484HIGH 8.2

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.

CVE-2021-35483MEDIUM 4.1

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript code is executed.

CVE-2025-10258MEDIUM 6.3

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.

CVE-2025-65885MEDIUM 5.1

An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowing local attackers to inject startup scripts via crafted .txt files in the :\Data directory.

CVE-2025-27020CRITICAL 9.8

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.

CVE-2025-27019CRITICAL 9.8

Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

CVE-2025-26489MEDIUM 6.5

Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

CVE-2025-26488HIGH 7.5

Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

CVE-2025-26487HIGH 8.6

Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge.

CVE-2025-24938HIGH 8.4

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) to the application has the potential execute commands on the operating system under the context of the webserver. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. Has the potential to inject command while creating a new User from User Management.

CVE-2025-24937CRITICAL 9.0

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.

CVE-2025-24936CRITICAL 9.0

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.

CVE-2025-27026MEDIUM 4.9

A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation via the WebGUI does not only stop CLI interface but deactivates also Linux Shell, WebGUI and Physical Serial Console access. No confirmation is asked at deactivation time. Loosing access to these services device administrators are at risk of completely loosing device control.

CVE-2025-27024MEDIUM 6.5

Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. Details: Account members of the Network Administrator profile can access the target machine via SFTP with the same credentials used for SSH CLI access and are able to read all files according to the OS permission instead of remaining inside the chrooted directory position.

CVE-2025-27023MEDIUM 6.5

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted CLI commands. Details: The web interface based management of the Infinera G42 appliance enables the feature of executing a restricted set of commands. This feature also offers the option to execute a script-file already present on the target device. When a non-script or incorrect file is specified, the content of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.

CVE-2025-27022HIGH 7.5

A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files via HTTP requests. Details: Lack or insufficient validation of user-supplied input allows authenticated users to access all files on the target machine file system that are readable to the user account used to run the httpd service.

CVE-2025-27021HIGH 7.0

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical memory via devmem command line tool. This could allow sensitive information disclosure, denial of service, and privilege escalation by tampering with kernel memory. Details: The output of "sudo -l" reports the presence of "devmem" command executable as super user without using a password. This command allows to read and write an arbitrary memory area of the target device, specifying an absolute address.

CVE-2024-25660CRITICAL 9.0

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

CVE-2024-25659HIGH 7.2

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.