Vulnerabilities
29 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-20252 | Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname p Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-40895 | In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. This affects NeDi 1.0.7 for OS X 1.0.7 <= and NeDi for Suse 1.0.7 <= and NeDi for FreeBSD 1.0.7 <=. NVD description · AI analysis pending | 9.1 | 2% | PoC |
| — | |
| CVE-2021-3822 | jsoneditor is vulnerable to Inefficient Regular Expression Complexity jsoneditor is vulnerable to Inefficient Regular Expression Complexity NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2021-26753 | NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data. NVD description · AI analysis pending | 9.9 group max | 1% | PoC |
| — | |
| CVE-2020-23849 | Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript. Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-23989 +1 in the same advisory: …23868 | NeDi 1.9C allows pwsec.php oid XSS. NeDi 1.9C allows pwsec.php oid XSS. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-15034 | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2020-14414 | NeDi 1.9C is vulnerable to Remote Command Execution. NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a pw parameter. (This can also be exploited via CSRF.) NVD description · AI analysis pending | 8.8 group max | 4% |
| — | ||
| CVE-2020-15017 +1 in the same advisory: …15016 | NeDi 1.9C is vulnerable to reflected cross-site scripting. NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the sta GET parameter. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2018-20727 | Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Tra Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv parameter to Devices-Graph.php, or the tit parameter to drawmap.php. NVD description · AI analysis pending | 8.8 group max | 6% | PoC |
| — |