Known Vulnerabilities for products from Nedi
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Nedi".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-40895 json | In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remot... | 9.1 - CRITICAL | 2022-10-06 | 2022-10-07 |
| CVE-2021-26753 json | NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via ... | 9.9 - CRITICAL | 2021-02-12 | 2022-05-03 |
| CVE-2021-26752 json | NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /No... | 8.8 - HIGH | 2021-02-12 | 2021-02-14 |
| CVE-2021-26751 json | NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitor... | 8.8 - HIGH | 2021-02-12 | 2021-02-14 |
| CVE-2020-23989 json | NeDi 1.9C allows pwsec.php oid XSS. | 5.4 - MEDIUM | 2020-11-02 | 2020-11-03 |
| CVE-2020-23868 json | NeDi 1.9C allows inc/rt-popup.php d XSS. | 5.4 - MEDIUM | 2020-11-02 | 2020-11-03 |
| CVE-2020-15037 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-10 |
| CVE-2020-15036 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-10 |
| CVE-2020-15035 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15034 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15033 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15032 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15031 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15030 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15029 json | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScr... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15028 json | NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaS... | 5.4 - MEDIUM | 2020-07-07 | 2020-07-09 |
| CVE-2020-15017 json | NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An at... | 6.1 - MEDIUM | 2020-06-26 | 2020-07-01 |
| CVE-2020-15016 json | NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An a... | 6.1 - MEDIUM | 2020-06-26 | 2020-07-01 |
| CVE-2020-14414 json | NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. A... | 8.8 - HIGH | 2020-06-29 | 2020-07-06 |
| CVE-2020-14413 json | NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempt... | 6.1 - MEDIUM | 2020-06-29 | 2020-07-06 |
Known software with vulnerabilities from Nedi
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Nedi | Nedi | 1.5 |