VYPR

Wd Discovery

by Westerndigital

CVEs (4)

  • CVE-2025-30248HigJan 26, 2026
    risk 0.58cvss epss 0.01

    DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path.

  • CVE-2020-15816HigJul 17, 2020
    risk 0.57cvss 8.8epss 0.04

    In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.

  • CVE-2020-12427HigMay 13, 2020
    risk 0.57cvss 8.8epss 0.00

    The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

  • CVE-2022-29835MedSep 19, 2022
    risk 0.34cvss 5.3epss 0.00

    WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality…