Loading HuntDB...

Western Digital

15 Products 42 CVEs

CVE Severity Distribution (All Time)

Critical
5
High
9
Medium
20
Low
4

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-22170 UNKNOWN 1 year, 1 month ago

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow…

CVE-2024-22169 UNKNOWN 1 year, 3 months ago

WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing th…

CVE-2024-22168 UNKNOWN 1 year, 5 months ago

A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker…

CVE-2023-22819 MEDIUM 1 year, 9 months ago

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memor…

CVE-2023-22817 MEDIUM 1 year, 9 months ago

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to …

CVE-2023-22814 CRITICAL 2 years, 4 months ago

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an i…

CVE-2023-22815 MEDIUM 2 years, 4 months ago

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t…

CVE-2023-22816 MEDIUM 2 years, 4 months ago

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b…

CVE-2022-36331 CRITICAL 2 years, 5 months ago

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an un…

CVE-2022-36328 MEDIUM 2 years, 6 months ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares …