Known Vulnerabilities for My Cloud Ex4 by Western Digital
Listed below are 1 of the newest known vulnerabilities associated with "My Cloud Ex4" by "Western Digital".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-95623 json | The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-94536 json | lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authe... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94535 json | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authentic... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94534 json | lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing ... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94533 json | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated us... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94532 json | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenti... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-93597 json | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and serv... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93031 json | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Ar... | Not Provided | 2026-09-18 | 2026-09-19 |
| CVE-2026-92808 json | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthe... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-92804 json | Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and p... | Not Provided | 2026-09-16 | 2026-09-21 |