CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Logitech Remove filter Clear all
CVE-2026-12518 HIGH

Local privilege escalation in the Logi Options+ updater service on Windows

CVSS 8.5 EPSS 0.11% Sep 14, 2026
CVE-2024-8258 LOW

Insecure Electron Fuses in Logitech Options Plus Allowing Arbitrary Code Execution on macOS

CVSS 2.0 EPSS 0.39% Sep 10, 2024
CVE-2024-8011 LOW

Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Op…

CVSS 2.0 EPSS 0.13% Aug 25, 2024
CVE-2024-4031 MEDIUM

MEVO WEBCAM APP Windows Unquoted Service Path Vulnerability

CVSS 4.4 EPSS 0.23% Apr 23, 2024
CVE-2024-2537 CRITICAL

Electron Code Injection in Logi Tune macOS Application

CVSS 9.8 EPSS 0.28% Mar 15, 2024
CVE-2022-36263 HIGH

StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.

CVSS 7.3 EPSS 0.40% Aug 19, 2022
CVE-2022-0916 HIGH

Broken authentication on Logitech Options due to misvalidation of Oauth state parameter

CVSS 8.8 EPSS 0.45% May 3, 2022
CVE-2022-0915 HIGH

Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation

CVSS 7.0 EPSS 0.18% Apr 12, 2022
CVE-2021-38547 MEDIUM

Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-o…

CVSS 5.9 EPSS 1.35% Aug 11, 2021
CVE-2021-20642 MEDIUM

Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a…

CVSS 6.5 EPSS 1.03% Feb 12, 2021
CVE-2021-20641 MEDIUM

Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially…

CVSS 6.5 EPSS 0.52% Feb 12, 2021
CVE-2021-20640 MEDIUM

Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vec…

CVSS 6.8 EPSS 0.56% Feb 12, 2021
CVE-2021-20639 MEDIUM

LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

CVSS 6.8 EPSS 0.46% Feb 12, 2021
CVE-2021-20638 MEDIUM

LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

CVSS 6.8 EPSS 0.46% Feb 12, 2021
CVE-2021-20637 MEDIUM

Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending…

CVSS 6.5 EPSS 1.03% Feb 12, 2021
CVE-2021-20636 MEDIUM

Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a speciall…

CVSS 6.5 EPSS 0.52% Feb 12, 2021
CVE-2021-20635 MEDIUM

Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and ac…

CVSS 6.5 EPSS 0.44% Feb 12, 2021
CVE-2019-13055 MEDIUM

Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions…

CVSS 6.5 EPSS 1.03% Jun 29, 2019
CVE-2019-13054 MEDIUM

The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using…

CVSS 6.5 EPSS 0.85% Jun 29, 2019
CVE-2019-13053 MEDIUM

Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data…

CVSS 6.5 EPSS 0.54% Jun 29, 2019
CVE-2016-10761 MEDIUM

Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

CVSS 6.5 EPSS 0.74% Jun 29, 2019
CVE-2019-13052 MEDIUM

Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.

CVSS 6.5 EPSS 0.67% Jun 29, 2019
CVE-2019-12506 HIGH

Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injecti…

CVSS 8.8 EPSS 1.35% Jun 7, 2019
CVE-2018-15723 CRITICAL

The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attac…

CVSS 9.8 EPSS 3.70% Dec 20, 2018
CVE-2018-15722 HIGH

The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can in…

CVSS 8.1 EPSS 1.64% Dec 20, 2018

Showing 1 to 25 CVEs · page 1 (more available)