Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nedi CRITICAL 9.1
CVE-2022-40895

In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the…

Fix: after 1.0.7
Fix from $2,300 2022-10-06
Nedi CRITICAL 9.9
CVE-2021-26753

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parame…

No fix yet
Fix from $2,300 2021-02-12
Nedi HIGH 8.8
CVE-2021-26751

NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the …

No fix yet
Fix from $1,950 2021-02-12
Nedi HIGH 8.8
CVE-2021-26752

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the …

No fix yet
Fix from $1,950 2021-02-12
Nedi MEDIUM 5.4
CVE-2020-23868

NeDi 1.9C allows inc/rt-popup.php d XSS.

No fix yet
Fix from $1,600 2020-11-02
Nedi MEDIUM 5.4
CVE-2020-23989

NeDi 1.9C allows pwsec.php oid XSS.

No fix yet
Fix from $1,600 2020-11-02
Nedi MEDIUM 5.4
CVE-2020-15028

NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topol…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15029

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15030

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topolog…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15031

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15032

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitor…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15033

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15034

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitor…

Mitigation only
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15035

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitor…

Patch available
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15037

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports…

Patch available
Fix from $1,600 2020-07-07
Nedi MEDIUM 5.4
CVE-2020-15036

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topolog…

Patch available
Fix from $1,600 2020-07-07
Nedi HIGH 8.8
CVE-2020-14412

NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can…

Mitigation only
Fix from $1,950 2020-06-29
Nedi HIGH 8.8
CVE-2020-14414

NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit t…

Mitigation only
Fix from $1,950 2020-06-29
Nedi MEDIUM 6.1
CVE-2020-14413

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT t…

Mitigation only
Fix from $1,600 2020-06-29
Nedi MEDIUM 6.1
CVE-2020-15016

NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this…

Mitigation only
Fix from $1,600 2020-06-26
Nedi MEDIUM 6.1
CVE-2020-15017

NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this …

Mitigation only
Fix from $1,600 2020-06-26
Nedi HIGH 8.8
CVE-2018-20727EPSS 6%

Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter t…

Fix: after 1.7c
Fix from $1,950 2019-01-17
Nedi HIGH 8.8
CVE-2018-20728

A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.

Fix: after 1.7c
Fix from $1,950 2019-01-17
Nedi HIGH 7.5
CVE-2018-20730

A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.

Fix: after 1.7c
Fix from $1,950 2019-01-17
Nedi MEDIUM 6.1
CVE-2018-20729

A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via the reg…

Fix: after 1.7c
Fix from $1,600 2019-01-17
Nedi MEDIUM 6.1
CVE-2018-20731

A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via User-Chat.…

Fix: after 1.7c
Fix from $1,600 2019-01-17