Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2018-14705
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing th…
5n2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-14699EPSS 29%
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec…
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14701EPSS 20%
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to exec…
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14703
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retr…
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14706EPSS 17%
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to e…
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14708
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14709
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure to…
5n2 Firmware
No fix yet
HIGH 7.5
CVE-2018-14695
Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve…
5n2 Firmware
No fix yet
HIGH 7.5
CVE-2018-14696
Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve…
5n2 Firmware
No fix yet
HIGH 7.5
CVE-2018-14700
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrie…
5n2 Firmware
No fix yet
HIGH 7.5
CVE-2018-14702
Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retri…
5n2 Firmware
No fix yet
HIGH 7.5
CVE-2018-14707EPSS 28%
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to a…
5n2 Firmware
No fix yet
MEDIUM 6.1
CVE-2018-14697
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via t…
5n2 Firmware
No fix yet
MEDIUM 6.1
CVE-2018-14698
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via t…
5n2 Firmware
No fix yet
MEDIUM 6.1
CVE-2018-14704
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed UR…
5n2 Firmware
No fix yet