Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firewall Community MEDIUM 5.4
CVE-2026-34821

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An auth…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34822

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authe…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34823

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated …

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34816

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An auth…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34817

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authen…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34818

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authen…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34819

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authentic…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34820

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacke…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34812

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenti…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34813

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated a…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34814

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34815

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticat…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34807

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated …

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34808

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticate…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34809

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated at…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34810

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated att…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34811

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated …

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34803

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated att…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34804

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attac…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34805

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated atta…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34806

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated atta…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34799

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34800

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticate…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34801

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authentic…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34802

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An a…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34796

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.c…

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34797

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi.…

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34798

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated a…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34794

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. …

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34795

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. …

Fix: after 3.3.25
Fix from $1,950 2026-04-02