Skip to main content

Vendor archive

sick CVEs

Beta · best-effort

123 CVEs tagged to vendor sick19 Critical, 37 High, 63 Medium, 4 Low, 0 Unrated.

CVE-2026-22646

Published Jan 15, 2026

Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance informa…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22645

Published Jan 15, 2026

The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilitie…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22644

Published Jan 15, 2026

Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22919

Published Jan 15, 2026

An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sens…

CVSS 3.8 · Low
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22918

Published Jan 15, 2026

An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extracti…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22916

Published Jan 15, 2026

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disrup…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22914

Published Jan 15, 2026

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22913

Published Jan 15, 2026

Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22912

Published Jan 15, 2026

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credent…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22910

Published Jan 15, 2026

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to th…

CVSS 7.5 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22909

Published Jan 15, 2026

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operation…

CVSS 7.5 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22908

Published Jan 15, 2026

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 123 CVEsPage 1 of 5