vciy

CVEs we hold for Nokia

Records whose assigning authority named Nokia as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-40465An Open Re-direct Vulnerability in Nokia NSPNokia NSP
CVE-2026-40464A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSPNokia NSP
CVE-2026-40463An Insufficient Role-based Access Control Vulnerability in WaveSuiteNokia WaveSuite
CVE-2025-9974Insufficient Input Validation on WEBUI in Nokia ONT/Beacon productNokia ONT
CVE-2025-9912A local privilege escalation vulnerability in Nokia SR LinuxNokia SR Linux
CVE-2025-7406A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NMNokia MantaRay NM
CVE-2025-24938Insufficient Validation of Input while user creationNokia WaveSuite NOC
CVE-2025-24937Access to local file system and its contentNokia WaveSuite NOC
CVE-2025-24936Insufficient Validation of Input in the URLNokia WaveSuite NOC
CVE-2025-24819A Relative Path Traversal vulnerability in Nokia MantaRay NMNokia MantaRay NM
CVE-2025-24818An OS Command Injection vulnerability in Nokia MantaRay NMNokia MantaRay NM
CVE-2025-24817An OS Command Injection vulnerability in Nokia MantaRay NMNokia MantaRay NM
CVE-2025-24816An Improper Access Control vulnerability in Nokia MantaRay NMNokia MantaRay NM
CVE-2025-24815An unrestricted file upload vulnerability in Nokia MantaRay NMNokia MantaRay NM
CVE-2025-24335SOAP message input validation fault could in theory cause OAM service resource exhaustionNokia Single RAN
CVE-2025-24334The Nokia Single RAN baseband reveals its software version through the MNO internal RAN management networkNokia Single RAN
CVE-2025-24333Administrative user shell input validation faultNokia Single RAN
CVE-2025-24332Authenticated admin user can connect baseband internally from one board to another without needing to re-authenticationNokia Single RAN AirScale (Flexi Multiradio is not affected)
CVE-2025-24331Nokia Single RAN baseband OAM service extensive capabilitiesNokia Single RAN
CVE-2025-24330OAM service path traversal issue caused by a crafted SOAP message PlanId field within the RAN management networkNokia Single RAN
CVE-2025-24329OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management networkNokia Single RAN
CVE-2025-24328OAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management networkNokia Single RAN
CVE-2025-10262An unsanitized format validation vulnerability in Nokia SR LinuxNokia SR Linux
CVE-2025-10258A time-based SQL Injection vulnerability in Infinera DNANokia Infinera DNA
CVE-2025-0980JSON RPC authentication bypass in Nokia SR LinuxNokia SR Linux
CVE-2023-6729Nokia SR OS: File Access Security VulnerabilityNokia SR OS (7250 IXR, 7450 ESS, 7750 SR, 7950 IXR, VSR)…
CVE-2023-6728Nokia SR OS: BOF File Encryption VulnerabilityNokia SR OS (7250 IXR, 7450 ESS, 7750 SR, 7950 IXR, VSR)…
CVE-2023-49565Remote Code ExecutionNokia CBIS,NCS
CVE-2023-49564Authentication BypassNokia CBIS,NCS
CVE-2022-2484no title heldNokia ASIK AirScale
CVE-2022-2483no title heldNokia ASIK AirScale
CVE-2022-2482no title heldNokia ASIK AirScale

32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.