netgear

1,325 tracked vulnerabilities.

CVE-2023-34563 CRITICAL
NETGEAR R6250 Firmware 1.0.4.48 - Authenticated Buffer Overflow
Jun 20, 2023
CVSS 9.8
EPSS 0.18
CVE-2023-33533 HIGH
Netgear D6220 D8500 R6700 R6900 - Authenticated Command Injection via Web Management Post Request
Jun 06, 2023
CVSS 8.8
EPSS 0.07
CVE-2023-33532 CRITICAL
Netgear R6250 <1.0.4.48 - Command Injection
Jun 06, 2023
CVSS 9.8
EPSS 0.27
CVE-2023-2396 MEDIUM
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via USERDBUsers.Password
Apr 28, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-2395 MEDIUM
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via Login.userAgent Parameter
Apr 28, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-2394 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via wanName Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2393 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via ConfigPort.LogicalIfName Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2392 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via ManualDate.minutes Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2391 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via ntp.server2 Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2390 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via NTP Server Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2389 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via smtpServer.emailServer Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2388 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via smtpServer.fromAddr Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2387 LOW
Netgear SRX5308 Firmware <= 4.3.5-3 - Cross-Site Scripting via winsServer1 Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2386 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via smtpServer.toAddr Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2385 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via IKE Policy Name Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2384 LOW
Netgear SRX5308 Firmware <= 4.3.5-3 - Cross-Site Scripting via dhcp.SecDnsIPByte2 Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.01
CVE-2023-2383 LOW
Netgear SRX5308 up to 4.3.5-3 - Cross-Site Scripting via smtpServer.fromAddr Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2382 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via sysLogInfo.serverName Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2381 LOW
Netgear SRX5308 <= 4.3.5-3 - Cross-Site Scripting via BandWidthProfile.ProfileName Parameter
Apr 28, 2023
CVSS 2.4
EPSS 0.00
CVE-2023-2380 MEDIUM
Netgear SRX5308 <= 4.3.5-3 - Denial of Service
Apr 28, 2023
CVSS 6.5
EPSS 0.01
CVE-2023-30280 CRITICAL
Netgear R6900 R6700 R6700v3 - Remote Code Execution and Denial of Service via fwSchedule.cgi getInputData Parameter
Apr 26, 2023
CVSS 9.8
EPSS 0.04
CVE-2023-28338 HIGH
Netgear Nighthawk Wifi6 Router (RAX30) - Denial of Service via Multipart Boundary Request
Mar 15, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-28337 HIGH
Netgear Nighthawk Wifi6 Router (RAX30) - Unrestricted Firmware Upload via Hidden forceFWUpdate Parameter
Mar 15, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-1327 CRITICAL
Netgear RAX30 Firmware < 1.0.6.74 - Unauthenticated Authentication Bypass via Password Reset
Mar 14, 2023
CVSS 9.8
EPSS 0.02
CVE-2023-27853 CRITICAL
NETGEAR Nighthawk WiFi6 Router < 1.0.10.94 - Remote Code Execution via SOAP Service Format String Vulnerability
Mar 10, 2023
CVSS 9.8
EPSS 0.01