Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-4701

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18
0
Attacker Value
Unknown

CVE-2023-3829

Disclosure Date: July 22, 2023 (last updated October 08, 2023)
A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/ticket/create of the component Support Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. VDB-235150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2022-34804

Disclosure Date: June 30, 2022 (last updated October 25, 2023)
Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.
Attacker Value
Unknown

CVE-2022-34803

Disclosure Date: June 30, 2022 (last updated October 25, 2023)
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2021-46704

Disclosure Date: March 06, 2022 (last updated February 23, 2025)
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.
Attacker Value
Unknown

CVE-2021-20172

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the software is going to be installed may overwrite certain files to obtain privilege escalation to root.
Attacker Value
Unknown

CVE-2021-24674

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack
Attacker Value
Unknown

CVE-2021-38702

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
Attacker Value
Unknown

CVE-2016-11058

Disclosure Date: April 28, 2020 (last updated February 21, 2025)
The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.
Attacker Value
Unknown

CVE-2013-1760

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities