Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-30568EPSS 47% Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. R6850 Firmware No fix yet Fix from $2,3002024-04-03 HIGH 8.0 CVE-2024-30572 Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter. R6850 Firmware No fix yet Fix from $1,9502024-04-03 HIGH 7.5 CVE-2024-30569 An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication requ… R6850 Firmware No fix yet Fix from $1,9502024-04-03 HIGH 7.5 CVE-2024-30571EPSS 14% An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authenticat… R6850 Firmware No fix yet Fix from $1,9502024-04-03 MEDIUM 5.3 CVE-2024-30570 An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required. R6850 Firmware No fix yet Fix from $1,6002024-04-03 HIGH 8.8 CVE-2023-50677 An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi compon… Dgnd4000 Firmware Mitigation only Fix from $1,9502024-03-14 HIGH 7.5 CVE-2024-28340 An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attacker… Cbk40 Firmware No fix yet Fix from $1,9502024-03-12 MEDIUM 5.4 CVE-2024-28339 An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to … Cbk40 Firmware No fix yet Fix from $1,6002024-03-12 HIGH 8.8 CVE-2023-48725EPSS 19% A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A sp… Rax30 Firmware No fix yet Fix from $1,9502024-03-07 MEDIUM 6.5 CVE-2024-1431 A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of… R7000 Firmware No fix yet Fix from $1,6002024-02-11 MEDIUM 6.5 CVE-2024-1430 A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown funct… R7000 Firmware No fix yet Fix from $1,6002024-02-11 CRITICAL 9.8 CVE-2023-50089 A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs dur… Wnr2000 Firmware No fix yet Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-49007EPSS 9% In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. Rbr750 Firmware 7.2.6.21+ Fix from $2,3002023-12-08 CRITICAL 9.8 CVE-2023-49693 NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticate… Prosafe Network Management System 1.7.0.34+ Fix from $2,3002023-11-29 HIGH 7.8 CVE-2023-49694 A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in… Prosafe Network Management System 1.7.0.31+ Fix from $1,9502023-11-29 CRITICAL 9.8 CVE-2023-36187 Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via craf… Cbr40 Firmware 1.0.1.70 / 1.0.4.118+ Fix from $2,3002023-09-01 HIGH 8.8 CVE-2023-39550 Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and … Jwnr2000v2 Firmware No fix yet Fix from $1,9502023-08-07 CRITICAL 9.8 CVE-2023-38928 Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. R7100lg Firmware Mitigation only Fix from $2,3002023-08-07 HIGH 8.8 CVE-2023-36499 Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi. Xr300 Firmware No fix yet Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38412 Netgear R6900P v1.3.3.154 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at ia_ap_setting.cgi. R6900p Firmware No fix yet Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38591 Netgear DG834Gv5 1.6.01.34 was discovered to contain multiple buffer overflows via the wla_ssid and wla_temp_ssid parameters at bsw_ssid.cgi. Dg834gv5 Firmware No fix yet Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38921 Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via… Wg302v2 Firmware Mitigation only Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38922 Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and … Jwnr2000v2 Firmware Mitigation only Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38925EPSS 15% Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.c… Dc112a Firmware Mitigation only Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-38926 Netgear EX6200 v1.0.3.94 was discovered to contain a buffer overflow via the wla_temp_ssid parameter at acosNvramConfig_set. Ex6200 Firmware No fix yet Fix from $1,9502023-08-07 MEDIUM 6.5 CVE-2023-38924 Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi. Dgn3500 Firmware Mitigation only Fix from $1,6002023-08-07 CRITICAL 9.8 CVE-2023-34563EPSS 14% netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication. R6250 Firmware No fix yet Fix from $2,3002023-06-20 CRITICAL 9.8 CVE-2023-33532EPSS 16% There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges… R6250 Firmware Mitigation only Fix from $2,3002023-06-06 HIGH 8.8 CVE-2023-33533 Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Ver… D6220 Firmware No fix yet Fix from $1,9502023-06-06 MEDIUM 6.1 CVE-2023-2395 A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the component Web Manageme… Srx5308 Firmware No fix yet Fix from $1,6002023-04-28