Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-23126 Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended action… Automate Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23128 Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Co… Connectwise Mitigation only Fix from $1,6002023-02-01 MEDIUM 5.9 CVE-2023-23130 Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the… Automate Mitigation only Fix from $1,6002023-02-01 MEDIUM 5.3 CVE-2023-23127 In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is … Connectwise Mitigation only Fix from $1,6002023-02-01 CRITICAL 9.8 CVE-2019-16517 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected t… Control No fix yet Fix from $2,3002020-01-23 HIGH 8.8 CVE-2019-16513 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests. Control No fix yet Fix from $1,9502020-01-23 HIGH 7.2 CVE-2019-16514 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administra… Control No fix yet Fix from $1,9502020-01-23 MEDIUM 6.5 CVE-2019-16515 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used. Control No fix yet Fix from $1,6002020-01-23 HIGH 8.8 CVE-2017-11726 services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by c… Manage No fix yet Fix from $1,9502017-07-31 MEDIUM 6.1 CVE-2017-11727 services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a Con… Manage No fix yet Fix from $1,6002017-07-31