Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-34821 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An auth… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34822 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authe… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34823 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated … Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34816 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An auth… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34817 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authen… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34818 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authen… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34819 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authentic… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34820 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacke… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34812 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenti… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34813 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated a… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34814 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34815 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticat… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34807 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated … Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34808 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticate… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34809 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated at… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34810 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated att… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34811 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated … Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34803 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated att… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34804 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attac… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34805 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated atta… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34806 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated atta… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34799 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34800 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticate… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34801 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authentic… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34802 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An a… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-34796 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.c… Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34797 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi.… Firewall Community after 3.3.25 Fix from $1,9502026-04-02 MEDIUM 5.4 CVE-2026-34798 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated a… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-34794 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. … Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34795 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. … Firewall Community after 3.3.25 Fix from $1,9502026-04-02