Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2023-1270
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
Btcpayserver
1.8.3+
MEDIUM 5.4
CVE-2023-1149
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
Btcpay Server
1.8.0+
MEDIUM 5.4
CVE-2023-0879
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
Btcpay Server
1.7.12+
MEDIUM 5.4
CVE-2023-0810
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
Btcpayserver
1.7.11+
MEDIUM 6.1
CVE-2023-0748
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
Btcpayserver
1.7.6+
MEDIUM 5.4
CVE-2023-0747
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
Btcpayserver
1.7.6+
HIGH 7.5
CVE-2022-32984
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive …
Btcpay Server
after 1.5.3
HIGH 8.8
CVE-2023-0493EPSS 8%
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
Btcpay Server
1.7.5+
MEDIUM 5.4
CVE-2021-3830
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Btcpay Server
after 1.2.3
MEDIUM 6.1
CVE-2021-3646
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Btcpay Server
1.2.3+
MEDIUM 6.7
CVE-2021-29246
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacke…
Btcpay Server
after 1.0.7.0
MEDIUM 5.4
CVE-2021-29250
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables …
Btcpay Server
after 1.0.7.0
MEDIUM 5.3
CVE-2021-29245
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
Btcpay Server
after 1.0.7.0
MEDIUM 5.3
CVE-2021-29247
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
Btcpay Server
after 1.0.7.0
MEDIUM 5.3
CVE-2021-29248
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
Btcpay Server
after 1.0.7.0
MEDIUM 6.5
CVE-2021-29251
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases…
Btcpay Server
1.0.7.1+
HIGH 7.5
CVE-2021-29249
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
Btcpay Server
1.0.6.0+