Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2023-22817 Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to … My Cloud Pr2100 Firmware 5.27.161+ Fix from $1,6002024-02-05 HIGH 7.8 CVE-2023-22818 Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local a… Sandisk Security Installer 1.0.0.25+ Fix from $1,9502023-11-15 CRITICAL 9.8 CVE-2023-22814 An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an i… My Cloud Os 5.26.202+ Fix from $2,3002023-07-01 HIGH 8.8 CVE-2023-22816 A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b… My Cloud Os 5.26.300+ Fix from $1,9502023-06-30 MEDIUM 6.7 CVE-2023-22815 Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t… My Cloud Os 5.26.300+ Fix from $1,6002023-06-30 HIGH 7.5 CVE-2022-36331 Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an un… My Cloud Pr2100 Firmware 5.25.132+ Fix from $1,9502023-06-12 CRITICAL 9.8 CVE-2022-36327 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations… My Cloud Os 5 5.26.202 / 9.4.0-191+ Fix from $2,3002023-05-18 MEDIUM 5.5 CVE-2022-29840 Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback… My Cloud Os 5.26.202+ Fix from $1,6002023-05-10 CRITICAL 9.8 CVE-2022-29841 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files… My Cloud Os 5.26.119+ Fix from $2,3002023-05-10 CRITICAL 9.8 CVE-2022-29842 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the… My Cloud Os 5.26.119+ Fix from $2,3002023-05-10 HIGH 7.5 CVE-2022-36329 An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Dig… My Cloud Home Firmware 9.4.0-191+ Fix from $1,9502023-05-10 HIGH 8.1 CVE-2022-36330 A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western … My Cloud Home Duo Firmware 9.4.0-191+ Fix from $1,9502023-05-10 HIGH 7.4 CVE-2023-22812 SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks there… Sandisk Privateaccess 6.4.9+ Fix from $1,9502023-03-24 CRITICAL 9.8 CVE-2021-36224 Western Digital My Cloud devices before OS5 have a nobody account with a blank password. My Cloud Os 5.02.104+ Fix from $2,3002023-02-06 CRITICAL 9.8 CVE-2021-36226 Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. My Cloud Os 5.02.104+ Fix from $2,3002023-02-06 HIGH 8.8 CVE-2021-36225 Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads an… My Cloud Os 5.02.104+ Fix from $1,9502023-02-06 CRITICAL 9.8 CVE-2022-29843 A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.… My Cloud Pr2100 Firmware 5.26.119+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-29844EPSS 36% A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read an… My Cloud Pr2100 Firmware 5.26.119+ Fix from $2,3002023-01-26 MEDIUM 5.5 CVE-2022-29839 Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker… My Cloud Os 5.25.124+ Fix from $1,6002022-12-09 HIGH 7.8 CVE-2022-29837 A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to ini… My Cloud Home Firmware 8.12.0-178+ Fix from $1,9502022-12-01 MEDIUM 6.7 CVE-2022-23006 A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attack… My Cloud Home Firmware 8.10.0-117+ Fix from $1,6002022-09-27 MEDIUM 5.3 CVE-2022-29835 WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certi… Wd Discovery 4.4.396+ Fix from $1,6002022-09-19 MEDIUM 5.3 CVE-2022-23001 When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user lev… Sweet B Mitigation only Fix from $1,6002022-07-29 MEDIUM 5.3 CVE-2022-23002 When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting output is not properly reduced… Sweet B Mitigation only Fix from $1,6002022-07-29 MEDIUM 5.3 CVE-2022-23003 When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not p… Sweet B Mitigation only Fix from $1,6002022-07-29 MEDIUM 5.3 CVE-2022-23004 When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned … Sweet B Mitigation only Fix from $1,6002022-07-29 HIGH 7.8 CVE-2022-23000 The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was e… My Cloud Pr2100 Firmware 5.23.114+ Fix from $1,9502022-07-25 CRITICAL 9.8 CVE-2022-22997 Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed … My Cloud Home Duo Firmware 8.5.1-102+ Fix from $2,3002022-07-12 HIGH 7.5 CVE-2022-22998 Implemented protections on AWS credentials that were not properly protected. My Cloud Home Duo Firmware 8.5.1-102+ Fix from $1,9502022-07-12 HIGH 7.8 CVE-2022-22996 The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary co… Sandisk Professional G Raid 4\/8 Software Utility 6.2.0.16-2 / 300520006-2+ Fix from $1,9502022-03-30