Loading HuntDB...

Milesight

16 Products 88 CVEs

CVE Severity Distribution (All Time)

Critical
6
High
70
Medium
6
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-36392 MEDIUM 1 year, 3 months ago

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-36391 CRITICAL 1 year, 3 months ago

MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic

CVE-2024-36390 HIGH 1 year, 3 months ago

MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service

CVE-2024-36389 CRITICAL 1 year, 3 months ago

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

CVE-2024-36388 CRITICAL 1 year, 3 months ago

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

CVE-2024-27776 CRITICAL 1 year, 3 months ago

MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE

CVE-2023-47166 HIGH 1 year, 4 months ago

A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request…

CVE-2023-43260 UNKNOWN 1 year, 11 months ago

Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.

CVE-2023-23550 HIGH 2 years, 2 months ago

An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network…

CVE-2023-23547 MEDIUM 2 years, 2 months ago

A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network re…