CVE Tools

Western-digital-corporation

5 CVEs tracked since 2015. Since Oct 2015, none of them reached CISA KEV.

Western-digital-corporation CVEs per month

Oct 2015 to Oct 2020. Point at a month, or focus the strip and use the arrow keys.
Western-digital-corporation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-1010
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-1040

Products

The products that kept showing up in Western-digital-corporation's monthly top three, with their CVEs summed over those months.

  1. Western Digital Mycloud Nas41 month
  2. Wd Arkeia11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Western-digital-corporation.

  1. CVE-2025-30247An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a sp...9.8
  2. CVE-2025-57699Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the sys...6.7
  3. CVE-2024-22170Unchecked buffer in Dynamic DNS client8.1
  4. CVE-2024-22169Misconfiguration in node.js causing a code execution in WD Discovery9.3
  5. CVE-2024-22167SanDisk PrivateAccess DLL Hijacking Vulnerability7.9
  6. CVE-2023-22819Uncontrolled resource consumption vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi products4.9
  7. CVE-2023-22817Server-side Request Forgery vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi products5.5
  8. CVE-2023-22818Multiple DLL Search Order hijacking Vulnerabilities in SanDisk Security Installer for Windows 7.3
  9. CVE-2023-22815Post-authentication remote command injection vulnerability on Western Digital My Cloud OS 5 devices6.2
  10. CVE-2023-22816Limited Post-Authentication Remote Command Injection in My Cloud Products6.0
  11. CVE-2022-36331Impersonation attack causing an Authentication Bypass on Western Digital devices10.0
  12. CVE-2022-36327Path traversal vulnerability leading to an arbitrary file write in Western Digital devices5.8
  13. CVE-2022-29841OS Command Injection vulnerability in Western Digital My Cloud devices8.0
  14. CVE-2021-36225Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.8.8
  15. CVE-2021-36226Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.9.8

The record

Peak rank
#101 in Oct 2020
Busiest month shown
Oct 2020, 4 CVEs
Months with a KEV entry
0 since Oct 2015
Monthly snapshots
2 since 2015
Western-digital-corporation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store