Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Xdmod CRITICAL 9.8
CVE-2026-45779

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3…

Fix: 10.0.3+
Fix from $2,300 2026-06-05
Open Xdmod CRITICAL 9.8
CVE-2026-45777

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remot…

Fix: 11.0.3+
Fix from $2,300 2026-06-05
Open Xdmod MEDIUM 5.4
CVE-2026-45778

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious Java…

Fix: 11.0.3+
Fix from $1,600 2026-06-05
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-27650

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be execut…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-32669

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-33280

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionali…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Wzr S900dhp Firmware HIGH 7.5
CVE-2026-32678

Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without aut…

Fix: 1.01 / 2.53+
Fix from $1,950 2026-03-27
Wcr 1166dhpl Firmware MEDIUM 5.3
CVE-2026-33366

Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product with…

Fix: 1.01 / 2.53+
Fix from $1,600 2026-03-27
Wsr 2533dhp Firmware CRITICAL 9.8
CVE-2024-23486

Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access…

Fix: 1.07 / 1.11+
Fix from $2,300 2024-04-15
Ls210d Firmware HIGH 7.2
CVE-2023-49038

Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as…

No fix yet
Fix from $1,950 2024-01-29
Ls210d Firmware HIGH 8.1
CVE-2023-51073

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifi…

No fix yet
Fix from $1,950 2024-01-11
Vr S1000 Firmware MEDIUM 6.5
CVE-2023-51363

VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain…

Fix: after 2.37
Fix from $1,600 2023-12-26
Vr S1000 Firmware HIGH 7.8
CVE-2023-46681

Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an…

Fix: after 2.37
Fix from $1,950 2023-12-26
Vr S1000 Firmware MEDIUM 6.8
CVE-2023-45741

VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands.

Fix: after 2.37
Fix from $1,600 2023-12-26
Terastation Nas 5410r Firmware HIGH 7.5
CVE-2023-39620

An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest a…

No fix yet
Fix from $1,950 2023-09-08
Bs Gsl2024 Firmware HIGH 7.5
CVE-2023-26588

Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected p…

Fix: after 1.10-0.03
Fix from $1,950 2023-04-11
Bs Gsl2024 Firmware HIGH 8.1
CVE-2023-24544

Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a res…

Fix: after 1.10-0.03
Fix from $1,950 2023-04-11
Bs Gs2008 Firmware MEDIUM 5.4
CVE-2023-24464

Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to e…

Fix: after 1.0.10.01
Fix from $1,600 2023-04-11
Wsr 3200ax4s Firmware HIGH 8.8
CVE-2022-43443

OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially c…

Fix: after 1.26
Fix from $1,950 2022-12-19
Wsr 3200ax4s Firmware MEDIUM 6.8
CVE-2022-43466

OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbit…

Fix: after 1.26
Fix from $1,600 2022-12-19
Wsr 3200ax4s Firmware MEDIUM 6.8
CVE-2022-43486

Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug…

Fix: after 1.26
Fix from $1,600 2022-12-19
Wcr 300 Firmware HIGH 8.8
CVE-2022-40966

Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the de…

Fix: after 2.96
Fix from $1,950 2022-12-07
Wcr 300 Firmware MEDIUM 6.8
CVE-2022-39044

Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute…

Fix: after 2.00
Fix from $1,600 2022-12-07
Wzr 300hp Firmware MEDIUM 6.5
CVE-2022-34840

Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of…

Fix: after 2.00
Fix from $1,600 2022-12-07
Wsr 1166dhp4 Firmware HIGH 8.8
CVE-2021-20731

WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands with root pr…

Fix: after 1.16
Fix from $1,950 2021-06-09
Wsr 2533dhpl2 Bk Firmware CRITICAL 9.8
CVE-2021-20090 KEVEPSS 100%

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 coul…

Fix: after 1.24
Fix from $2,300 2021-04-29
Wsr 2533dhpl2 Bk Firmware HIGH 8.8
CVE-2021-20091EPSS 9%

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. A…

Fix: after 1.24
Fix from $1,950 2021-04-29
Wsr 2533dhpl2 Bk Firmware HIGH 7.5
CVE-2021-20092EPSS 8%

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sen…

Fix: after 1.24
Fix from $1,950 2021-04-29
Bhr 4rv Firmware CRITICAL 9.8
CVE-2021-20716

Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware …

Fix: after 2.55
Fix from $2,300 2021-04-28
Bhr 4grv Firmware HIGH 8.8
CVE-2021-3512

Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, …

Fix: 1.84 / 1.87+
Fix from $1,950 2021-04-28