Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2022-22992
A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute ar…
My Cloud Os
5.19.117+
CRITICAL 9.8
CVE-2022-22994
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading thro…
My Cloud Os
5.19.117+
HIGH 8.8
CVE-2022-22993
A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any pa…
My Cloud Os
5.19.117+
CRITICAL 9.8
CVE-2022-22989
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attack…
My Cloud Os
5.19.117+
CRITICAL 9.1
CVE-2022-22988
File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for …
Edgerover
1.5.0-576+
HIGH 8.8
CVE-2022-22990
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on…
My Cloud Os
5.19.117+
HIGH 8.8
CVE-2022-22991
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecure…
My Cloud Os
5.19.117+
HIGH 7.5
CVE-2021-35941EPSS 13%
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory re…
Wd My Book Live Firmware
No fix yet
HIGH 8.8
CVE-2021-33205
Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into dir…
Edgerover
0.25+
MEDIUM 6.5
CVE-2021-28653
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storag…
Armorlock
1.4.1+
HIGH 7.8
CVE-2021-3310
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and in…
My Cloud Os
5.10.122+
CRITICAL 9.8
CVE-2020-29563
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unau…
My Cloud Os 5
5.07.118+
HIGH 7.8
CVE-2020-29654
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
Dashboard
3.2.2.9+
CRITICAL 9.8
CVE-2020-28971
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unau…
My Cloud Os 5
5.06.115+
CRITICAL 9.8
CVE-2020-28940
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unau…
My Cloud Os 5
5.06.115+
CRITICAL 9.8
CVE-2020-28970
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unau…
My Cloud Os 5
5.06.115+
MEDIUM 6.8
CVE-2020-13799
Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for s…
Inand Cl Em132 Firmware
after 2020-06-03
CRITICAL 9.8
CVE-2020-27744EPSS 6%
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privil…
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-27158EPSS 7%
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5…
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-27159EPSS 6%
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western …
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-27160
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prio…
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-12830
Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remo…
My Cloud Firmware
5.04.114+
CRITICAL 9.8
CVE-2020-25765EPSS 6%
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prio…
My Cloud Firmware
5.04.114+
HIGH 8.8
CVE-2020-15816
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in th…
Wd Discovery
4.0.251.0+
HIGH 8.8
CVE-2020-12427
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealin…
Wd Discovery
3.8.229+
HIGH 7.5
CVE-2019-10705
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be dec…
Sandisk X600 Sd9tb8w 128g Firmware
Mitigation only
MEDIUM 6.3
CVE-2019-10706
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The…
Sandisk X600 Sd9tb8w 128g Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-11686
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically …
Sandisk X600 Sd9tb8w 128g Firmware
Mitigation only
MEDIUM 6.1
CVE-2020-8960
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
Mycloud.com
2.2.0-134+
HIGH 7.8
CVE-2020-8959
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
Sandiskssddashboardsetup.exe
3.0.2.0+