Записи nedi
26 опубликованных записей вендора nedi.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-203 Observable Discrepancy1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-863 Incorrect Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-26753Эксплойта нет | NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POnedi · nedi · CWE-863 | Критическая9,9 | — | 1,2 % | 12 февр. 2021 г. |
37Наблюдать | CVE-2018-20727Эксплойта нет | Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt panedi · nedi · CWE-78 | Высокая8,8 | — | 5,6 % | 16 янв. 2019 г. |
37Наблюдать | CVE-2022-40895Эксплойта нет | In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to anedi · nedi · CWE-203 | Критическая9,1 | — | 1,8 % | 6 окт. 2022 г. |
36Наблюдать | CVE-2020-14412Эксплойта нет | NeDi 1.9C is vulnerable to Remote Command Execution.nedi · nedi · CWE-78 | Высокая8,8 | — | 3,7 % | 29 июн. 2020 г. |
36Наблюдать | CVE-2020-14414Эксплойта нет | NeDi 1.9C is vulnerable to Remote Command Execution.nedi · nedi · CWE-78 | Высокая8,8 | — | 3,7 % | 29 июн. 2020 г. |
35Наблюдать | CVE-2021-26752Эксплойта нет | NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.phpnedi · nedi · CWE-78 | Высокая8,8 | — | 1,5 % | 12 февр. 2021 г. |
35Наблюдать | CVE-2021-26751Эксплойта нет | NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.phpnedi · nedi · CWE-89 | Высокая8,8 | — | 1,2 % | 12 февр. 2021 г. |
35Наблюдать | CVE-2018-20728Эксплойта нет | A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.pnedi · nedi · CWE-352 | Высокая8,8 | — | 0,6 % | 16 янв. 2019 г. |
30Наблюдать | CVE-2018-20730Эксплойта нет | A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.nedi · nedi · CWE-89 | Высокая7,5 | — | 1,2 % | 16 янв. 2019 г. |
25Наблюдать | CVE-2020-14413Proof of concept | NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php.nedi · nedi · CWE-79 | Средняя6,1 | — | 3,4 % | 29 июн. 2020 г. |
24Наблюдать | CVE-2018-20731Эксплойта нет | A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via Unedi · nedi · CWE-79 | Средняя6,1 | — | 0,8 % | 16 янв. 2019 г. |
24Наблюдать | CVE-2018-20729Эксплойта нет | A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML vinedi · nedi · CWE-79 | Средняя6,1 | — | 0,8 % | 16 янв. 2019 г. |
24Наблюдать | CVE-2020-15017Эксплойта нет | NeDi 1.9C is vulnerable to reflected cross-site scripting.nedi · nedi · CWE-79 | Средняя6,1 | — | 0,6 % | 26 июн. 2020 г. |
24Наблюдать | CVE-2020-15016Эксплойта нет | NeDi 1.9C is vulnerable to reflected cross-site scripting.nedi · nedi · CWE-79 | Средняя6,1 | — | 0,6 % | 26 июн. 2020 г. |
21Наблюдать | CVE-2020-15032Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15034Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15028Эксплойта нет | NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15030Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15029Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15031Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15033Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-23989Эксплойта нет | NeDi 1.9C allows pwsec.php oid XSS.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,6 % | 2 нояб. 2020 г. |
21Наблюдать | CVE-2020-15036Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,5 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15037Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,5 % | 7 июл. 2020 г. |
21Наблюдать | CVE-2020-15035Эксплойта нет | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Средняя5,4 | — | 0,5 % | 7 июл. 2020 г. |
- CVE-2021-2675339Наблюдать
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP PO
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %nedi · nedi12 февр. 2021 г.
- CVE-2018-2072737Наблюдать
Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt pa
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %nedi · nedi16 янв. 2019 г.
- CVE-2022-4089537Наблюдать
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %nedi · nedi6 окт. 2022 г.
- CVE-2020-1441236Наблюдать
NeDi 1.9C is vulnerable to Remote Command Execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %nedi · nedi29 июн. 2020 г.
- CVE-2020-1441436Наблюдать
NeDi 1.9C is vulnerable to Remote Command Execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %nedi · nedi29 июн. 2020 г.
- CVE-2021-2675235Наблюдать
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nedi · nedi12 февр. 2021 г.
- CVE-2021-2675135Наблюдать
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nedi · nedi12 февр. 2021 г.
- CVE-2018-2072835Наблюдать
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.p
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nedi · nedi16 янв. 2019 г.
- CVE-2018-2073030Наблюдать
A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nedi · nedi16 янв. 2019 г.
- CVE-2020-1441325Наблюдать
NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php.
СредняяCVSS 6,1Proof of conceptEPSS 3 %nedi · nedi29 июн. 2020 г.
- CVE-2018-2073124Наблюдать
A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via U
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nedi · nedi16 янв. 2019 г.
- CVE-2018-2072924Наблюдать
A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nedi · nedi16 янв. 2019 г.
- CVE-2020-1501724Наблюдать
NeDi 1.9C is vulnerable to reflected cross-site scripting.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nedi · nedi26 июн. 2020 г.
- CVE-2020-1501624Наблюдать
NeDi 1.9C is vulnerable to reflected cross-site scripting.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nedi · nedi26 июн. 2020 г.
- CVE-2020-1503221Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1503421Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1502821Наблюдать
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1503021Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1502921Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1503121Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1503321Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-2398921Наблюдать
NeDi 1.9C allows pwsec.php oid XSS.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi2 нояб. 2020 г.
- CVE-2020-1503621Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1503721Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.
- CVE-2020-1503521Наблюдать
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %nedi · nedi7 июл. 2020 г.