CVE-2022-40895
- EPSS 1.37%
- Veröffentlicht 06.10.2022 18:16:54
- Zuletzt bearbeitet 21.11.2024 07:22:13
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure des...
CVE-2021-26753
- EPSS 0.58%
- Veröffentlicht 12.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:56:48
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to ...
CVE-2021-26752
- EPSS 1.16%
- Veröffentlicht 12.02.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:56:47
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where N...
CVE-2021-26751
- EPSS 0.37%
- Veröffentlicht 12.02.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:56:47
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain acc...
CVE-2020-23989
- EPSS 0.21%
- Veröffentlicht 02.11.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:18
NeDi 1.9C allows pwsec.php oid XSS.
CVE-2020-23868
- EPSS 0.21%
- Veröffentlicht 02.11.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:08
NeDi 1.9C allows inc/rt-popup.php d XSS.
CVE-2020-15029
- EPSS 0.34%
- Veröffentlicht 07.07.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:39
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.
CVE-2020-15035
- EPSS 0.34%
- Veröffentlicht 07.07.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:40
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Map.php hde parameter.
CVE-2020-15034
- EPSS 0.34%
- Veröffentlicht 07.07.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:40
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.
CVE-2020-15033
- EPSS 0.34%
- Veröffentlicht 07.07.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:40
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget.php ip parameter.