Western Digital
First CVE: Jan 13, 2022Active for: 5 years
49
CVEs Published
More CVEs Published than 57% of tracked CNAs
9.8
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 68% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Western Digital as a CNA, 0.0% affect products that Western Digital develops as a vendor.
100.0%
Self-reported: 0Third-party: 49
Of all the CVEs published that affect products developed by Western Digital, 0.0% are self-published by Western Digital as a CNA.
100.0%
Self-published: 0Published by other CNAs: 8
Trends Over Time
The number and severity of CVEs published by Western Digital over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2022
4 years ago
Most Recent CVE
Jan 26, 2026
180 days ago
Top CVEs
All CVEs published by Western Digital as a CNA, regardless of affected vendor or product.
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29844CRITICAL A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This c | Jan 26, 2023 | 9.8 | 51 | NO | NO |
CVE-2025-30247CRITICAL An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system | Sep 29, 2025 | 9.3 | 34 | NO | NO |
CVE-2022-36327CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesyst | May 18, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-29842CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a | May 10, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-22995CRITICAL The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacke | Mar 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-22992CRITICAL A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the | Jan 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-30248HIGH DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in t | Jan 26, 2026 | 8.9 | 30 | NO | NO |
CVE-2022-29841CRITICAL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and | May 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-22994CRITICAL A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. Thi | Jan 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-22170CRITICAL Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My | Sep 27, 2024 | 9.2 | 29 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA49 CVEs
37%
35%
29%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (20.4%)
Network35 (71.4%)
Unknown0 (0.0%)
Physical1 (2.0%)
Adjacent Network3 (6.1%)
Attack Complexity
Low43 (87.8%)
High6 (12.2%)
Unknown0 (0.0%)
User Interaction
None40 (81.6%)
Unknown0 (0.0%)
Required6 (12.2%)
Privileges Required
Low9 (18.4%)
High6 (12.2%)
None34 (69.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Western Digital as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Western Digital as a CNA — matched by CVE ID, not by organization name.