Filtered by vendor Endian
Subscribe
Total
37 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-34818 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34798 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34811 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34822 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34802 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34806 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34800 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34817 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34823 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34793 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 8.8 HIGH |
| Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation. | |||||
| CVE-2026-34813 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34808 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34795 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 8.8 HIGH |
| Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation. | |||||
| CVE-2026-34810 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34803 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34821 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34816 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34819 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34814 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34797 | 1 Endian | 1 Firewall Community | 2026-07-24 | N/A | 8.8 HIGH |
| Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation. | |||||
