Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-29090 ### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.crea… Rucio 35.8.5 / 38.5.5+ Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-29080 A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend … Rucio 35.8.5 / 38.5.5+ Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-33046 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to … Indico 3.3.12+ Fix from $1,9502026-03-23 MEDIUM 6.5 CVE-2026-28352 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API… Indico 3.3.11+ Fix from $1,6002026-02-27 MEDIUM 6.1 CVE-2026-25136 Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie… Rucio 35.8.3 / 38.5.4+ Fix from $1,6002026-02-25 MEDIUM 5.4 CVE-2026-25733 Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie… Rucio 35.8.3 / 38.5.4+ Fix from $1,6002026-02-25 MEDIUM 5.3 CVE-2026-25138 Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie… Rucio 35.8.3 / 38.5.4+ Fix from $1,6002026-02-25 MEDIUM 5.4 CVE-2026-25739 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnera… Indico 3.3.10+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2025-59035 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a C… Indico 3.3.8+ Fix from $1,6002025-09-10 MEDIUM 6.5 CVE-2025-53640 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to… Indico 3.3.7+ Fix from $1,6002025-07-14 HIGH 7.5 CVE-2024-50633 A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST reque… Indico after 3.3.2 Fix from $1,9502025-01-16 MEDIUM 6.1 CVE-2024-45399 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, co… Indico 3.3.4+ Fix from $1,6002024-09-04 MEDIUM 5.4 CVE-2023-37901 Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts co… Indico 3.2.6+ Fix from $1,6002023-07-21 HIGH 7.5 CVE-2021-30185 CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. Indico 2.3.4+ Fix from $1,9502021-04-07 HIGH 8.8 CVE-2017-1000203 ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution Root after 6.9.03 Fix from $1,9502017-11-17