Skip to main content

Vendor archive

buffalo CVEs

Beta · best-effort

61 CVEs tagged to vendor buffalo8 Critical, 30 High, 23 Medium, 0 Low, 0 Unrated.

CVE-2026-45779

Published Jun 5, 2026

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticate…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-45778

Published Jun 5, 2026

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD u…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45777

Published Jun 5, 2026

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system c…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-45776

Published Jun 5, 2026

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafte…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2023-51073

Published Jan 11, 2024

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51363

Published Dec 26, 2023

VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24464

Published Apr 11, 2023

Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on…

CVSS 5.4 · Medium
Showing 1-25 of 61 CVEsPage 1 of 3