Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Nas Os CRITICAL 9.8
CVE-2018-12295

SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL param…

No fix yet
Fix from $2,300 2019-05-13
Nas Os HIGH 7.5
CVE-2018-12296EPSS 11%

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information ab…

No fix yet
Fix from $1,950 2019-05-13
Nas Os HIGH 7.5
CVE-2018-12298

Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.

No fix yet
Fix from $1,950 2019-05-13
Nas Os HIGH 7.5
CVE-2018-12301

Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.…

Mitigation only
Fix from $1,950 2019-05-13
Nas Os MEDIUM 6.1
CVE-2018-12297

Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

No fix yet
Fix from $1,600 2019-05-13
Nas Os MEDIUM 6.1
CVE-2018-12300

Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta…

No fix yet
Fix from $1,600 2019-05-13
Nas Os MEDIUM 6.1
CVE-2018-12302

Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-si…

Mitigation only
Fix from $1,600 2019-05-13
Nas Os MEDIUM 6.1
CVE-2018-12304

Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metada…

No fix yet
Fix from $1,600 2019-05-13
Nas Os MEDIUM 5.4
CVE-2018-12299

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

No fix yet
Fix from $1,600 2019-05-13
Nas Os MEDIUM 5.4
CVE-2018-12303

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

No fix yet
Fix from $1,600 2019-05-13
Blackarmor Nas 220 Firmware CRITICAL 9.8
CVE-2014-3205

backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

No fix yet
Fix from $2,300 2018-02-23
Blackarmor Nas 220 Firmware CRITICAL 9.8
CVE-2014-3206EPSS 51%

Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_na…

No fix yet
Fix from $2,300 2018-02-23
Personal Cloud Firmware CRITICAL 9.8
CVE-2018-5347EPSS 54%

Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because…

No fix yet
Fix from $2,300 2018-01-12
Blackarmor Nas 220 Firmware CRITICAL 9.8
CVE-2013-6924EPSS 15%

Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip…

No fix yet
Fix from $2,300 2017-10-11
Business Nas Firmware CRITICAL 9.8
CVE-2014-8687EPSS 44%

Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use …

No fix yet
Fix from $2,300 2017-06-08
Blackarmor Nas 220 Firmware MEDIUM 6.8
CVE-2013-6922

Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote atta…

No fix yet
Fix from $1,600 2014-01-21
Blackarmor Nas HIGH 10.0
CVE-2012-2568

d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrato…

Mitigation only
Fix from $1,950 2012-05-25