📦

webaccess

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 29 Remote Access
Total CVEs 431 Total Indexed
Avg. EPSS 5.62% Exploit Prob.
Latest CVE CVE-2023-4215 Oct 17

Security Vulnerability Index

Page 10 / 44
9.8 CVSS

Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: 28.19%
9.8 CVSS
CVE-2016-0856
Exploit Found

Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: 16.65%
7.5 CVSS

Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.

EPSS: 4.69%
9.8 CVSS
CVE-2016-0854
Exploit Found

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

EPSS: 77.04%
7.5 CVSS

Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

EPSS: 2.26%
7.5 CVSS

Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.

EPSS: 2.41%
7.5 CVSS

Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

EPSS: 2.23%
8.1 CVSS

Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.

EPSS: 3.76%
5.4 CVSS

Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 0.97%
8.1 CVSS

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

EPSS: 1.69%