Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,177
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 21 - 34 of 34 CVEs
CVE-2026-34803 MEDIUM - 6.4

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34802 MEDIUM - 6.4

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34801 MEDIUM - 6.4

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34800 MEDIUM - 6.4

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34799 MEDIUM - 6.4

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34798 MEDIUM - 6.4

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34797 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete re...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34796 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34795 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete reg...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34794 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete reg...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34793 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplet...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34792 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete ...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34791 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete r...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34790 HIGH - 7.1

Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, whic...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD