Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 36333 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-45507 1 Netgear 20 Cbr40, Cbr40 Firmware, Cbr750 and 17 more 2026-06-17 7.5 HIGH 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBW30 before 2.6.2.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, and RBS40V before 2.6.2.8.
CVE-2021-45506 1 Netgear 14 Cbr750, Cbr750 Firmware, Rbk752 and 11 more 2026-06-17 5.8 MEDIUM 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
CVE-2021-45505 1 Netgear 14 Cbr750, Cbr750 Firmware, Rbk752 and 11 more 2026-06-17 5.8 MEDIUM 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
CVE-2021-45504 1 Netgear 10 Cbr40, Cbr40 Firmware, Cbr750 and 7 more 2026-06-17 7.5 HIGH 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
CVE-2021-45503 1 Netgear 14 Cbr750, Cbr750 Firmware, Rbk752 and 11 more 2026-06-17 5.8 MEDIUM 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
CVE-2021-45502 1 Netgear 14 Cbr750, Cbr750 Firmware, Rbk752 and 11 more 2026-06-17 5.8 MEDIUM 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
CVE-2021-45501 1 Netgear 38 Ac2400, Ac2400 Firmware, Ac2600 and 35 more 2026-06-17 10.0 HIGH 9.4 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects AC2400 before 1.1.0.84, AC2600 before 1.1.0.84, D7000 before 1.0.1.82, R6020 before 1.0.0.52, R6080 before 1.0.0.52, R6120 before 1.0.0.80, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260 before 1.1.0.84, R6330 before 1.1.0.84, R6350 before 1.1.0.84, R6700v2 before 1.1.0.84, R6800 before 1.1.0.84, R6850 before 1.1.0.84, R6900v2 before 1.1.0.84, R7200 before 1.1.0.84, R7350 before 1.1.0.84, R7400 before 1.1.0.84, and R7450 before 1.1.0.84.
CVE-2021-45500 1 Netgear 4 R7000p, R7000p Firmware, R8000 and 1 more 2026-06-17 5.8 MEDIUM 9.6 CRITICAL
Certain NETGEAR devices are affected by authentication bypass. This affects R7000P before 1.3.3.140 and R8000 before 1.0.4.68.
CVE-2021-45499 1 Netgear 14 R6900p, R6900p Firmware, R7000p and 11 more 2026-06-17 6.5 MEDIUM 8.2 HIGH
Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.
CVE-2021-45498 1 Netgear 2 R6700v2, R6700v2 Firmware 2026-06-17 10.0 HIGH 6.5 MEDIUM
NETGEAR R6700v2 devices before 1.2.0.88 are affected by authentication bypass.
CVE-2021-45497 1 Netgear 2 D7000, D7000 Firmware 2026-06-17 10.0 HIGH 9.4 CRITICAL
NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.
CVE-2021-45496 1 Netgear 2 D7000, D7000 Firmware 2026-06-17 10.0 HIGH 9.1 CRITICAL
NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.
CVE-2021-45495 1 Netgear 2 D7000, D7000 Firmware 2026-06-17 10.0 HIGH 6.5 MEDIUM
NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.
CVE-2021-45494 1 Netgear 6 Rbk352, Rbk352 Firmware, Rbr350 and 3 more 2026-06-17 2.7 LOW 8.4 HIGH
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.
CVE-2021-45471 2 Fedoraproject, Mediawiki 2 Fedora, Mediawiki 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
CVE-2021-45467 1 Control-webpanel 1 Webpanel 2026-06-17 N/A 9.8 CRITICAL
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.
CVE-2021-45463 4 Fedoraproject, Gegl, Gimp and 1 more 4 Fedora, Gegl, Gimp and 1 more 2026-06-17 6.8 MEDIUM 7.8 HIGH
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
CVE-2021-45461 1 Sangoma 3 Freepbx, Pbxact, Restapps 2026-06-17 7.5 HIGH 9.8 CRITICAL
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.
CVE-2021-45454 1 Amperecomputing 4 Ampere Altra, Ampere Altra Firmware, Ampere Altra Max and 1 more 2026-06-17 N/A 7.5 HIGH
Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.
CVE-2021-45444 4 Apple, Debian, Fedoraproject and 1 more 5 Mac Os X, Macos, Debian Linux and 2 more 2026-06-17 5.1 MEDIUM 7.8 HIGH
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.