Show filters
88 Total Results
Displaying 1-10 of 88
Sort by:
Attacker Value
Unknown
CVE-2023-32220
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
1
Attacker Value
Unknown
CVE-2024-36392
Disclosure Date: June 02, 2024 (last updated June 03, 2024)
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2024-36391
Disclosure Date: June 02, 2024 (last updated June 03, 2024)
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
0
Attacker Value
Unknown
CVE-2024-36390
Disclosure Date: June 02, 2024 (last updated June 03, 2024)
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
0
Attacker Value
Unknown
CVE-2024-36389
Disclosure Date: June 02, 2024 (last updated June 03, 2024)
MileSight DeviceHub -
CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
0
Attacker Value
Unknown
CVE-2024-36388
Disclosure Date: June 02, 2024 (last updated June 03, 2024)
MileSight DeviceHub -
CWE-305 Missing Authentication for Critical Function
0
Attacker Value
Unknown
CVE-2024-27776
Disclosure Date: June 02, 2024 (last updated June 03, 2024)
MileSight DeviceHub -
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
0
Attacker Value
Unknown
CVE-2023-47166
Disclosure Date: May 01, 2024 (last updated January 05, 2025)
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-43260
Disclosure Date: October 05, 2023 (last updated October 12, 2023)
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
0
Attacker Value
Unknown
CVE-2023-43261
Disclosure Date: October 04, 2023 (last updated October 12, 2023)
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
0