Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Cerebrate
MEDIUM 5.3
CVE-2023-41908
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
Fix: 1.15+
Fix from $1,600
2023-09-05
Cerebrate
CRITICAL 9.8
CVE-2023-28883
In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.
Patch available
Fix from $2,300
2023-03-27
Cerebrate
CRITICAL 9.1
CVE-2023-26468
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.
Patch available
Fix from $2,300
2023-02-24
Cerebrate
MEDIUM 6.1
CVE-2022-25317
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
Fix: after 1.4
Fix from $1,600
2022-02-18
Cerebrate
MEDIUM 6.1
CVE-2022-25321
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
Fix: after 1.4
Fix from $1,600
2022-02-18
Cerebrate
MEDIUM 5.3
CVE-2022-25319
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
Fix: after 1.4
Fix from $1,600
2022-02-18
Cerebrate
MEDIUM 5.3
CVE-2022-25320
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
Fix: after 1.4
Fix from $1,600
2022-02-18