Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2020-6627EPSS 12%
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_la…
Stcg2000300 Firmware
Patch available
HIGH 7.5
CVE-2021-43429
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->l…
Cortx S3 Server
Patch available
CRITICAL 9.8
CVE-2018-12295
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL param…
Nas Os
No fix yet
HIGH 7.5
CVE-2018-12296EPSS 11%
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information ab…
Nas Os
No fix yet
HIGH 7.5
CVE-2018-12298
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
Nas Os
No fix yet
HIGH 7.5
CVE-2018-12301
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.…
Nas Os
Mitigation only
MEDIUM 6.1
CVE-2018-12297
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
Nas Os
No fix yet
MEDIUM 6.1
CVE-2018-12300
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta…
Nas Os
No fix yet
MEDIUM 6.1
CVE-2018-12302
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-si…
Nas Os
Mitigation only
MEDIUM 6.1
CVE-2018-12304
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metada…
Nas Os
No fix yet
MEDIUM 5.4
CVE-2018-12299
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
Nas Os
No fix yet
MEDIUM 5.4
CVE-2018-12303
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
Nas Os
No fix yet
HIGH 7.5
CVE-2017-18263
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
Personal Cloud Firmware
4.3.18.4+
CRITICAL 9.8
CVE-2014-3205
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
Blackarmor Nas 220 Firmware
No fix yet
CRITICAL 9.8
CVE-2014-3206EPSS 51%
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_na…
Blackarmor Nas 220 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-5347EPSS 54%
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because…
Personal Cloud Firmware
No fix yet
CRITICAL 9.8
CVE-2013-6924EPSS 15%
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip…
Blackarmor Nas 220 Firmware
No fix yet
CRITICAL 9.8
CVE-2014-8687EPSS 44%
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use …
Business Nas Firmware
No fix yet
HIGH 7.5
CVE-2015-2875
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie F…
Goflex Sattelite
after 2.3.0.014
CRITICAL 9.8
CVE-2015-2874
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.10…
Wireless Mobile Storage
after 2.3.0.014
MEDIUM 6.8
CVE-2013-6922
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote atta…
Blackarmor Nas 220 Firmware
No fix yet
HIGH 10.0
CVE-2012-2568
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrato…
Blackarmor Nas
Mitigation only