CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “digi”

353 vulnerabilities found for “digi”

Page 1 of 18

CVE-2025-12082
HIGH7.5

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

salsa.digital / civictheme_design_system
Network
Published Oct 30, 2025
Page 1 of 18
CVE-2025-12083
MEDIUM6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme Design System allows Cross-Site Scripting (XSS).This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

salsa.digital / civictheme_design_system
Network
Published Oct 30, 2025
CVE-2025-59717
MEDIUM5.4

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).

digitalocean / do-markdownit
Network
Published Sep 19, 2025
CVE-2020-12733
HIGH7.5

Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.

depstech / wifi_digital_microscope_3_firmware
Network
Published Jul 15, 2021
CVE-2020-12732
MEDIUM6.5

DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.

depstech / wifi_digital_microscope_3_firmware
Adjacent
Published Jul 15, 2021
CVE-2020-12734
HIGH8.1

DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Default settings.

depstech / wifi_digital_microscope_3_firmware
Adjacent
Published Jul 15, 2021
CVE-2019-11686
MEDIUM5.5

Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.

westerndigital / sandisk_x600_sd9tb8w-128g_firmware+58
Local
Published Mar 10, 2020
CVE-2019-10705
HIGH7.5

Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.

westerndigital / sandisk_x600_sd9tb8w-128g_firmware+19
Network
Published Mar 10, 2020
CVE-2019-10706
MEDIUM6.3

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

westerndigital / sandisk_x600_sd9tb8w-128g_firmware+58
Local
Published Mar 10, 2020
CVE-2020-6973
MEDIUM6.2

Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Multiple cross-site scripting vulnerabilities exist that could allow an attacker to cause a denial-of-service condition.

digi / connectport_lts_32_mei_bios+1
Network
Published Feb 13, 2020
CVE-2020-6975
MEDIUM4.9

Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful exploitation of this vulnerability could allow an attacker to upload a malicious file to the application.

digi / connectport_lts_32_mei_bios+1
Network
Published Feb 12, 2020
CVE-2019-15425
LOW3.3

The Kata M4s Android device with a build fingerprint of alps/full_hct6750_66_n/hct6750_66_n:7.0/NRD90M/1495624556:user/test-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.

katadigital / m4s_firmware
Local
Published Nov 14, 2019
CVE-2015-9507
MEDIUM6.1

The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

awesomemotive / easy_digital_downloads+6
Network
Published Oct 23, 2019
CVE-2019-13467
MEDIUM5.9

Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources with arbitrary files.

sandisk / ssd_dashboard+1
Network
Published Sep 30, 2019
CVE-2019-13466
HIGH7.5

Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available.

sandisk / ssd_dashboard+1
Network
Published Sep 30, 2019
CVE-2019-9949
HIGH8.8

Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks. Specifically, this occurs by uploading a tar archive that contains a symbolic link, then uploading another archive that writes a file to the link using the "cgi_untar" command. Other commands might also be susceptible. Code can be executed because the "name" parameter passed to the cgi_unzip command is not sanitized.

westerndigital / my_cloud_firmware+8
Network
Published May 23, 2019
CVE-2019-9950
CRITICAL9.8

Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file checks credentials against /etc/shadow. However, the "nobody" account (which can be used to access the control panel API as a low-privilege logged-in user) has a default empty password, allowing an attacker to modify the My Cloud EX2 Ultra web page source code and obtain access to the My Cloud as a non-Admin My Cloud device user.

westerndigital / my_cloud_firmware+8
Network
Published Apr 24, 2019
CVE-2018-19524
CRITICAL9.8

An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.

skyworthdigital / dt740_firmware+2
Network
Published Mar 21, 2019
CVE-2018-13652
HIGH7.5

The mintToken function of a smart contract implementation for TheGoDigital, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

thegodigital_project / thegodigital
Network
Published Jul 9, 2018
CVE-2018-10173
HIGH8.8

Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.

digitalguardian / management_console
Network
Published Apr 20, 2018