CVE-2025-53509
- EPSS 0.04%
- Published 10.07.2025 23:29:10
- Last modified 01.08.2025 19:16:23
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a c...
CVE-2025-52459
- EPSS 0.05%
- Published 10.07.2025 23:28:08
- Last modified 15.07.2025 13:14:49
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a comman...
CVE-2025-53515
- EPSS 0.19%
- Published 10.07.2025 23:25:51
- Last modified 01.08.2025 19:13:59
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are...
CVE-2025-52577
- EPSS 0.19%
- Published 10.07.2025 23:24:42
- Last modified 23.07.2025 19:20:13
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input paramete...
CVE-2025-53475
- EPSS 0.19%
- Published 10.07.2025 23:23:38
- Last modified 23.07.2025 19:19:37
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters ...
CVE-2025-46704
- EPSS 0.05%
- Published 10.07.2025 23:19:32
- Last modified 23.07.2025 19:20:26
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not pr...
CVE-2025-48891
- EPSS 0.06%
- Published 10.07.2025 23:17:45
- Last modified 23.07.2025 19:20:18
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading...
CVE-2025-41442
- EPSS 0.04%
- Published 10.07.2025 23:15:27
- Last modified 23.07.2025 19:20:42
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's ...
CVE-2025-53519
- EPSS 0.04%
- Published 10.07.2025 23:14:37
- Last modified 23.07.2025 19:19:55
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's brows...
CVE-2025-53397
- EPSS 0.04%
- Published 10.07.2025 23:13:27
- Last modified 01.08.2025 19:19:25
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentia...