Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nedi vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-40895
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote malicious user to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a differe...
Nedi Nedi
Nedi Nedi 1.0.7
578
VMScore
CVE-2018-20727
Multiple command injection vulnerabilities in NeDi prior to 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv parameter to Devices-Graph.php, or the tit parameter to drawmap.php.
Nedi Nedi
383
VMScore
CVE-2018-20729
A reflected cross site scripting (XSS) vulnerability in NeDi prior to 1.7Cp3 allows remote malicious users to inject arbitrary web script or HTML via the reg parameter in mh.php.
Nedi Nedi
383
VMScore
CVE-2018-20731
A stored cross site scripting (XSS) vulnerability in NeDi prior to 1.7Cp3 allows remote malicious users to inject arbitrary web script or HTML via User-Chat.php.
Nedi Nedi
605
VMScore
CVE-2018-20728
A cross site request forgery (CSRF) vulnerability in NeDi prior to 1.7Cp3 allows remote malicious users to escalate privileges via User-Management.php.
Nedi Nedi
445
VMScore
CVE-2018-20730
A SQL injection vulnerability in NeDi prior to 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.
Nedi Nedi
578
VMScore
CVE-2021-26752
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an malicious user to obtain access to the operating system where NeDi is installed and to ...
Nedi Nedi 1.9c
356
VMScore
CVE-2021-26751
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an malicious user to access all the data in the database and obtain access to the NeDi applicat...
Nedi Nedi 1.9c
578
VMScore
CVE-2021-26753
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an malicious user to obtain access to the operating system where NeDi is installed and to all application data.
Nedi Nedi 1.9c
383
VMScore
CVE-2020-15016
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the txt GET parameter.
Nedi Nedi 1.9c
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »