CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-45663

    Last Modified: 21 Nov 2024

    NETGEAR R7000 devices before 1.0.11.126 are affected by stored XSS.

    Published: 26 Dec 2021
    5.6
    Medium

    CVE-2021-45664

    Last Modified: 21 Nov 2024

    NETGEAR R7000 devices before 1.0.11.126 are affected by stored XSS.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45665

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, RBW30 before 2.6.1.4, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, and RBS40V before 2.6.1.4.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45666

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, RBW30 before 2.6.1.4, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, and RBS40V before 2.6.1.4.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45667

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, RAX200 before 1.0.3.106, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, EX3700 before 1.0.0.90, MR60 before 1.0.6.110, R8000P before 1.4.1.66, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, EX3800 before 1.0.0.90, MS60 before 1.0.6.110, R7900P before 1.4.1.66, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45668

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX45 before 1.0.2.72, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.

    Published: 26 Dec 2021
    3.7
    Low

    CVE-2021-45669

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45670

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before 1.0.11.116, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.3.106, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, EX3700 before 1.0.0.90, MR60 before 1.0.6.110, R7000P before 1.3.2.126, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, EX3800 before 1.0.0.90, MS60 before 1.0.6.110, R6900P before 1.3.2.126, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45671

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.62, EX7500 before 1.0.0.72, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.4.120, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.4.120, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.4.120, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

    Published: 26 Dec 2021
    4.2
    Medium

    CVE-2021-45672

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by Stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260 before 1.1.0.78, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R6700v2 before 1.2.0.76, R6850 before 1.1.0.78, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, AC2600 before 1.2.0.76, and RAX40 before 1.0.3.62.

    Published: 26 Dec 2021
    4.8
    Medium

    CVE-2021-45673

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P before 1.3.3.140, and RAX75 before 1.0.3.106.

    Published: 26 Dec 2021
    3.2
    Low

    CVE-2021-45674

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.

    Published: 26 Dec 2021
    5.8
    Medium

    CVE-2021-45675

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6850 before 1.1.0.78, R6350 before 1.1.0.78, R6330 before 1.1.0.78, R6800 before 1.2.0.76, R6700v2 before 1.2.0.76, R6900v2 before 1.2.0.76, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, and AC2600 before 1.2.0.76.

    Published: 26 Dec 2021
    4.3
    Medium

    CVE-2021-45676

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.5.126, RAX20 before 1.0.2.82, RAX80 before 1.0.5.126, RAX15 before 1.0.2.82, and RAX75 before 1.0.5.126.

    Published: 26 Dec 2021
    5.2
    Medium

    CVE-2021-45677

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects GS108Tv2 before 5.4.2.36 and GS110TPv2 before 5.4.2.36.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45678

    Last Modified: 21 Nov 2024

    NETGEAR RAX200 devices before 1.0.5.132 are affected by insecure code.

    Published: 26 Dec 2021
    8.4
    High

    CVE-2021-45679

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by privilege escalation. This affects R6900P before 1.3.3.140, R7000 before 1.0.11.126, R7000P before 1.3.3.140, and RS400 before 1.5.1.80.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2018-25023

    Last Modified: 21 Nov 2024

    An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

    Published: 26 Dec 2021
    7.1
    High

    CVE-2022-0144

    Last Modified: 21 Nov 2024

    shelljs is vulnerable to Improper Privilege Management

    Published: 26 Dec 2021
    5.5
    Medium

    CVE-2022-0382

    Last Modified: 21 Nov 2024

    An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1.

    Published: 26 Dec 2021
    8.2
    High

    CVE-2021-35055

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37560

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37561

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37584

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37563

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-32467

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-32468

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-32469

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915 Affected Software Versions 7.4.0.0; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37562

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37566

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7610, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37569

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37568

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37583

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37571

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds write).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37567

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37565

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37564

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37570

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).

    Published: 25 Dec 2021
    8.2
    High

    CVE-2021-37572

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Missing authorization).

    Published: 25 Dec 2021
    6.5
    Medium

    CVE-2021-41788

    Last Modified: 21 Nov 2024

    MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

    Published: 25 Dec 2021
    4.3
    Medium

    CVE-2021-4162

    Last Modified: 21 Nov 2024

    archivy is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 25 Dec 2021
    7.5
    High

    CVE-2021-45484

    Last Modified: 21 Nov 2024

    In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.

    Published: 25 Dec 2021
    7.5
    High

    CVE-2021-45487

    Last Modified: 21 Nov 2024

    In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.

    Published: 25 Dec 2021
    7.5
    High

    CVE-2021-45488

    Last Modified: 21 Nov 2024

    In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.

    Published: 25 Dec 2021
    7.5
    High

    CVE-2021-45489

    Last Modified: 21 Nov 2024

    In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.

    Published: 25 Dec 2021
    7.1
    High

    CVE-2021-4166

    Last Modified: 21 Nov 2024

    vim is vulnerable to Out-of-bounds Read

    Published: 25 Dec 2021
    5.4
    Medium

    CVE-2021-3977

    Last Modified: 21 Nov 2024

    invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 24 Dec 2021
    7.5
    High

    CVE-2021-23490

    Last Modified: 21 Nov 2024

    The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.

    Published: 24 Dec 2021
    7.5
    High

    CVE-2021-23574

    Last Modified: 21 Nov 2024

    All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).

    Published: 24 Dec 2021
    5.4
    Medium

    CVE-2021-4072

    Last Modified: 21 Nov 2024

    elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 24 Dec 2021