Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-6627EPSS 12% The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_la… Stcg2000300 Firmware Patch available Fix from $2,3002022-12-06 HIGH 7.5 CVE-2021-43429 A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->l… Cortx S3 Server Patch available Fix from $1,9502022-04-07 CRITICAL 9.8 CVE-2018-12295 SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL param… Nas Os No fix yet Fix from $2,3002019-05-13 HIGH 7.5 CVE-2018-12296EPSS 11% Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information ab… Nas Os No fix yet Fix from $1,9502019-05-13 HIGH 7.5 CVE-2018-12298 Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path. Nas Os No fix yet Fix from $1,9502019-05-13 HIGH 7.5 CVE-2018-12301 Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.… Nas Os Mitigation only Fix from $1,9502019-05-13 MEDIUM 6.1 CVE-2018-12297 Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names. Nas Os No fix yet Fix from $1,6002019-05-13 MEDIUM 6.1 CVE-2018-12300 Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta… Nas Os No fix yet Fix from $1,6002019-05-13 MEDIUM 6.1 CVE-2018-12302 Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-si… Nas Os Mitigation only Fix from $1,6002019-05-13 MEDIUM 6.1 CVE-2018-12304 Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metada… Nas Os No fix yet Fix from $1,6002019-05-13 MEDIUM 5.4 CVE-2018-12299 Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names. Nas Os No fix yet Fix from $1,6002019-05-13 MEDIUM 5.4 CVE-2018-12303 Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names. Nas Os No fix yet Fix from $1,6002019-05-13 HIGH 7.5 CVE-2017-18263 Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url. Personal Cloud Firmware 4.3.18.4+ Fix from $1,9502018-04-28 CRITICAL 9.8 CVE-2014-3205 backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user. Blackarmor Nas 220 Firmware No fix yet Fix from $2,3002018-02-23 CRITICAL 9.8 CVE-2014-3206EPSS 51% Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_na… Blackarmor Nas 220 Firmware No fix yet Fix from $2,3002018-02-23 CRITICAL 9.8 CVE-2018-5347EPSS 54% Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… Personal Cloud Firmware No fix yet Fix from $2,3002018-01-12 CRITICAL 9.8 CVE-2013-6924EPSS 15% Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip… Blackarmor Nas 220 Firmware No fix yet Fix from $2,3002017-10-11 CRITICAL 9.8 CVE-2014-8687EPSS 44% Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use … Business Nas Firmware No fix yet Fix from $2,3002017-06-08 HIGH 7.5 CVE-2015-2875 Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie F… Goflex Sattelite after 2.3.0.014 Fix from $1,9502015-12-31 CRITICAL 9.8 CVE-2015-2874 Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.10… Wireless Mobile Storage after 2.3.0.014 Fix from $2,3002015-12-31 MEDIUM 6.8 CVE-2013-6922 Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote atta… Blackarmor Nas 220 Firmware No fix yet Fix from $1,6002014-01-21 HIGH 10.0 CVE-2012-2568 d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrato… Blackarmor Nas Mitigation only Fix from $1,9502012-05-25