VulnSea

ilevia has 8 CVEs on record. The median CVSS is 8.2 (high), with 3 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
8.2
Publish → KEV
—
Last 90 days
0 prev 0

Products

  • eve_x1_server_firmware 8
8
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

ilevia vulnerabilities

CVEs affecting ilevia, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2025-34519High· 7.5
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a fast, unsalted ha…

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a fast, unsalted ha…

▾ Twilightilevia · eve_x1_server_firmwareEPSS 0.31%via NVD
CVE-2025-34518High· 7.5
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recomm…

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recomm…

▾ Twilightilevia · eve_x1_server_firmwareEPSS 0.66%via NVD
CVE-2025-34517High· 7.5
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recom…

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recom…

▾ Twilightilevia · eve_x1_server_firmwareEPSS 0.66%via NVD
CVE-2025-34516Critical· 9.8
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends …

▾ Midnightilevia · eve_x1_server_firmwareEPSS 0.58%via NVD
CVE-2025-34515Critical· 9.8
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerab…

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerab…

▾ Midnightilevia · eve_x1_server_firmwareEPSS 8.0%via NVD
CVE-2025-34514High· 8.8
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. …

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. …

▾ Twilightilevia · eve_x1_server_firmwareEPSS 2.0%via NVD
CVE-2025-34513Critical· 9.8
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulner…

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulner…

▾ Midnightilevia · eve_x1_server_firmwareEPSS 7.6%via NVD
CVE-2025-34512Medium· 6.1
11mo ago

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser. Ilevia has decl…

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser. Ilevia has decl…

▾ Sunlitilevia · eve_x1_server_firmwareEPSS 0.41%via NVD
ilevia vulnerabilities (CVEs) · VulnSea