• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-13322
2018-12-26
N/A
6.5 MEDIUM
Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory contents via the "path" parameter.
CVE-2018-13321
2019-10-03
N/A
8.8 HIGH
Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "method" parameter.
CVE-2018-13320
2019-10-03
N/A
7.2 HIGH
System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execute system commands via the adminUsername and adminPassword parameters.
CVE-2018-1332
2018-07-13
N/A
6.5 MEDIUM
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
CVE-2018-13319
2018-12-31
N/A
7.5 HIGH
Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensitive device information via an unauthenticated POST request.
CVE-2018-13318
2019-10-03
N/A
7.2 HIGH
System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute system commands via the "name" parameter.
CVE-2018-13317
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2018-12-20
N/A
6.1 MEDIUM
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
CVE-2018-13316
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2019-10-03
N/A
9.8 CRITICAL
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.
CVE-2018-13315
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2018-12-20
N/A
9.8 CRITICAL
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
CVE-2018-13314
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2019-10-03
N/A
9.8 CRITICAL
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.
« Previous 1 … 2,613 2,614 2,615 2,616 2,617 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE