🛡️ CVE Intelligence Center
Common Vulnerabilities & Exposures — Security Intelligence Database
| CVE ID | Severity | CVSS | Description | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-34804 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/r…
|
— | Apr 2, 2026 |
| CVE-2026-34805 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dn…
|
— | Apr 2, 2026 |
| CVE-2026-34806 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/sn…
|
— | Apr 2, 2026 |
| CVE-2026-34807 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/in…
|
— | Apr 2, 2026 |
| CVE-2026-34808 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/ou…
|
— | Apr 2, 2026 |
| CVE-2026-34809 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zo…
|
— | Apr 2, 2026 |
| CVE-2026-34810 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vp…
|
— | Apr 2, 2026 |
| CVE-2026-34811 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xt…
|
— | Apr 2, 2026 |
| CVE-2026-34812 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin…
|
— | Apr 2, 2026 |
| CVE-2026-34823 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/pas…
|
— | Apr 2, 2026 |
| CVE-2026-34818 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dns…
|
— | Apr 2, 2026 |
| CVE-2026-0688 | Medium | 6.4 |
The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5…
|
— | Apr 2, 2026 |
| CVE-2026-34817 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-b…
|
— | Apr 2, 2026 |
| CVE-2026-34819 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/op…
|
— | Apr 2, 2026 |
| CVE-2026-34820 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ips…
|
— | Apr 2, 2026 |
| CVE-2026-34816 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smt…
|
— | Apr 2, 2026 |
| CVE-2026-34815 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/sm…
|
— | Apr 2, 2026 |
| CVE-2026-34814 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/pro…
|
— | Apr 2, 2026 |
| CVE-2026-34822 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /man…
|
— | Apr 2, 2026 |
| CVE-2026-34813 | Medium | 6.4 |
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/prox…
|
— | Apr 2, 2026 |