Seagate
18 CVEs tracked since 2012. Since May 2012, none of them reached CISA KEV.
Seagate CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2012-05 | 1 | 0 |
| 2012-06 | null or fewer | |
| 2012-07 | null or fewer | |
| 2012-08 | null or fewer | |
| 2012-09 | null or fewer | |
| 2012-10 | null or fewer | |
| 2012-11 | null or fewer | |
| 2012-12 | null or fewer | |
| 2013-01 | null or fewer | |
| 2013-02 | null or fewer | |
| 2013-03 | null or fewer | |
| 2013-04 | null or fewer | |
| 2013-05 | null or fewer | |
| 2013-06 | null or fewer | |
| 2013-07 | null or fewer | |
| 2013-08 | null or fewer | |
| 2013-09 | null or fewer | |
| 2013-10 | null or fewer | |
| 2013-11 | null or fewer | |
| 2013-12 | null or fewer | |
| 2014-01 | 2 | 0 |
| 2014-02 | null or fewer | |
| 2014-03 | null or fewer | |
| 2014-04 | null or fewer | |
| 2014-05 | null or fewer | |
| 2014-06 | null or fewer | |
| 2014-07 | null or fewer | |
| 2014-08 | null or fewer | |
| 2014-09 | null or fewer | |
| 2014-10 | null or fewer | |
| 2014-11 | null or fewer | |
| 2014-12 | null or fewer | |
| 2015-01 | null or fewer | |
| 2015-02 | null or fewer | |
| 2015-03 | null or fewer | |
| 2015-04 | null or fewer | |
| 2015-05 | null or fewer | |
| 2015-06 | null or fewer | |
| 2015-07 | null or fewer | |
| 2015-08 | null or fewer | |
| 2015-09 | null or fewer | |
| 2015-10 | null or fewer | |
| 2015-11 | null or fewer | |
| 2015-12 | 3 | 0 |
| 2016-01 | null or fewer | |
| 2016-02 | null or fewer | |
| 2016-03 | null or fewer | |
| 2016-04 | null or fewer | |
| 2016-05 | null or fewer | |
| 2016-06 | null or fewer | |
| 2016-07 | null or fewer | |
| 2016-08 | null or fewer | |
| 2016-09 | null or fewer | |
| 2016-10 | null or fewer | |
| 2016-11 | null or fewer | |
| 2016-12 | null or fewer | |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | null or fewer | |
| 2017-04 | null or fewer | |
| 2017-05 | null or fewer | |
| 2017-06 | null or fewer | |
| 2017-07 | null or fewer | |
| 2017-08 | null or fewer | |
| 2017-09 | null or fewer | |
| 2017-10 | null or fewer | |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | null or fewer | |
| 2018-02 | 2 | 0 |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | 10 | 0 |
Products
The products that kept showing up in Seagate's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Seagate.
- CVE-2025-9267In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their...6.5
- CVE-2025-9043The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Se...—
- CVE-2020-6627The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_he...9.8
- CVE-2021-43429A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.7.5
- CVE-2018-12304Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Pu...6.1
- CVE-2018-12303Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.5.4
- CVE-2018-12302Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.6.1
- CVE-2018-12301Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.7.5
- CVE-2018-12300Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.6.1
- CVE-2018-12299Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.5.4
- CVE-2018-12298Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.7.5
- CVE-2018-12297Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.6.1
- CVE-2018-12296Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POS...7.5
- CVE-2018-12295SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.9.8
- CVE-2017-18263Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.7.5
The record
- Peak rank
- #42 in May 2019
- Busiest month shown
- May 2019, 10 CVEs
- Months with a KEV entry
- 0 since May 2012
- Monthly snapshots
- 5 since 2012