İçeriğe atla
Noroxi

nedi kayıtları

nedi üreticisine ait 26 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

26 kayıt
  • CVE-2021-26753
    39İzleyin

    NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP PO

    KritikCVSS 9,9İstismar yokEPSS %1

    nedi · nedi12 Şub 2021

  • CVE-2018-20727
    37İzleyin

    Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt pa

    YüksekCVSS 8,8İstismar yokEPSS %6

    nedi · nedi16 Oca 2019

  • CVE-2022-40895
    37İzleyin

    In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a

    KritikCVSS 9,1İstismar yokEPSS %2

    nedi · nedi6 Eki 2022

  • CVE-2020-14412
    36İzleyin

    NeDi 1.9C is vulnerable to Remote Command Execution.

    YüksekCVSS 8,8İstismar yokEPSS %4

    nedi · nedi29 Haz 2020

  • CVE-2020-14414
    36İzleyin

    NeDi 1.9C is vulnerable to Remote Command Execution.

    YüksekCVSS 8,8İstismar yokEPSS %4

    nedi · nedi29 Haz 2020

  • CVE-2021-26752
    35İzleyin

    NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php

    YüksekCVSS 8,8İstismar yokEPSS %1

    nedi · nedi12 Şub 2021

  • CVE-2021-26751
    35İzleyin

    NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php

    YüksekCVSS 8,8İstismar yokEPSS %1

    nedi · nedi12 Şub 2021

  • CVE-2018-20728
    35İzleyin

    A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.p

    YüksekCVSS 8,8İstismar yokEPSS %1

    nedi · nedi16 Oca 2019

  • CVE-2018-20730
    30İzleyin

    A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.

    YüksekCVSS 7,5İstismar yokEPSS %1

    nedi · nedi16 Oca 2019

  • CVE-2020-14413
    25İzleyin

    NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php.

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    nedi · nedi29 Haz 2020

  • CVE-2018-20731
    24İzleyin

    A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via U

    OrtaCVSS 6,1İstismar yokEPSS %1

    nedi · nedi16 Oca 2019

  • CVE-2018-20729
    24İzleyin

    A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML vi

    OrtaCVSS 6,1İstismar yokEPSS %1

    nedi · nedi16 Oca 2019

  • CVE-2020-15017
    24İzleyin

    NeDi 1.9C is vulnerable to reflected cross-site scripting.

    OrtaCVSS 6,1İstismar yokEPSS %1

    nedi · nedi26 Haz 2020

  • CVE-2020-15016
    24İzleyin

    NeDi 1.9C is vulnerable to reflected cross-site scripting.

    OrtaCVSS 6,1İstismar yokEPSS %1

    nedi · nedi26 Haz 2020

  • CVE-2020-15032
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15034
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15028
    21İzleyin

    NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15030
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15029
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15031
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15033
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-23989
    21İzleyin

    NeDi 1.9C allows pwsec.php oid XSS.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi2 Kas 2020

  • CVE-2020-15036
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15037
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020

  • CVE-2020-15035
    21İzleyin

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nedi · nedi7 Tem 2020