Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xerte Online Toolkits CRITICAL 9.8
CVE-2026-32985

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t…

Fix: after 3.14.0
Fix from $2,300 2026-03-20
Opencast MEDIUM 5.4
CVE-2025-61788

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, the paell…

Fix: 17.8 / 18.2+
Fix from $1,600 2025-10-08
Opencast MEDIUM 5.3
CVE-2025-55202

Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, …

Fix: 17.7+
Fix from $1,600 2025-08-29
Opencast MEDIUM 6.5
CVE-2025-54380

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco…

Fix: 17.6+
Fix from $1,600 2025-07-26
Central Authentication Service HIGH 7.5
CVE-2025-3986

A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\cor…

Mitigation only
Fix from $1,950 2025-04-27
Central Authentication Service HIGH 7.5
CVE-2025-3984

A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\we…

Mitigation only
Fix from $1,950 2025-04-27
Opencast HIGH 7.5
CVE-2024-52797

Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch…

Fix: 13.10 / 14.3+
Fix from $1,950 2024-11-21
Central Authentication Service CRITICAL 9.8
CVE-2024-11209

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the compo…

No fix yet
Fix from $2,300 2024-11-14
Central Authentication Service HIGH 8.1
CVE-2024-11208

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?se…

No fix yet
Fix from $1,950 2024-11-14
Central Authentication Service MEDIUM 5.4
CVE-2024-11207

A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the fil…

No fix yet
Fix from $1,600 2024-11-14
Central Authentication Service CRITICAL 9.1
CVE-2024-4399

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

No fix yet
Fix from $2,300 2024-05-23
Opencast HIGH 7.5
CVE-2018-16153

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitra…

Fix: 10.6+
Fix from $1,950 2023-12-12
Central Authentication Service CRITICAL 9.8
CVE-2023-4612

Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authenticatio…

Fix: 7.0.0+
Fix from $2,300 2023-11-09
Central Authentication Service HIGH 7.5
CVE-2023-28857

Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50…

Fix: 6.5.9.1 / 6.6.6+
Fix from $1,950 2023-06-27
Opencast MEDIUM 6.1
CVE-2022-41965

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella …

Fix: 12.5+
Fix from $1,600 2022-11-28
Opencast MEDIUM 5.4
CVE-2022-29237

Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass…

Fix: 10.14 / 11.7+
Fix from $1,600 2022-05-24
Opencast HIGH 7.7
CVE-2021-43821

Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URL…

Fix: 10.6+
Fix from $1,950 2021-12-14
Opencast MEDIUM 6.5
CVE-2021-43807

Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to …

Fix: 9.10+
Fix from $1,600 2021-12-14
Central Authentication Service MEDIUM 6.1
CVE-2021-42567EPSS 8%

Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.

Fix: 6.3.7.1 / 6.4.2+
Fix from $1,600 2021-12-07
Opencast MEDIUM 6.5
CVE-2021-32623

Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the bil…

Fix: 9.6+
Fix from $1,600 2021-06-16
Opencast MEDIUM 5.4
CVE-2021-21318

Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a …

Fix: 9.2+
Fix from $1,600 2021-02-18
Central Authentication Service HIGH 7.5
CVE-2020-27178

Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator f…

Fix: 5.3.16 / 6.1.7.2+
Fix from $1,950 2020-10-16
Opencast CRITICAL 10.0
CVE-2020-5206

In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that use…

Fix: 7.6+
Fix from $2,300 2020-01-30
Opencast MEDIUM 6.5
CVE-2020-5231

In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE…

Fix: 7.6+
Fix from $1,600 2020-01-30
Opencast HIGH 7.5
CVE-2020-5230

Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and…

Fix: 7.6+
Fix from $1,950 2020-01-30
Opencast HIGH 8.8
CVE-2020-5222

Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This mean…

Fix: 7.6+
Fix from $1,950 2020-01-30
Opencast HIGH 8.1
CVE-2020-5229

Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted …

Fix: 8.1+
Fix from $1,950 2020-01-30
Opencast HIGH 7.5
CVE-2020-5228

Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workfl…

Fix: 7.6+
Fix from $1,950 2020-01-30
Central Authentication Service HIGH 8.1
CVE-2019-10754

Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation whic…

Fix: after 6.0.5.1
Fix from $1,950 2019-09-23
Bw Calendar Engine CRITICAL 9.0
CVE-2018-1000836

bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can res…

Fix: after 3.12.0
Fix from $2,300 2018-12-20