Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crafty Controller CRITICAL 9.1
CVE-2026-13716

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path…

Fix: 4.10.8+
Fix from $5,750 2026-08-11
Crafty Controller CRITICAL 9.0
CVE-2026-5652

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform …

Fix: 4.10.4+
Fix from $2,300 2026-04-21
Crafty Controller HIGH 8.8
CVE-2026-0963

An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to p…

Mitigation only
Fix from $1,950 2026-01-30
Crafty Controller HIGH 8.8
CVE-2026-0805

An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform f…

Fix: 4.8.0+
Fix from $1,950 2026-01-30
Crafty Controller CRITICAL 9.9
CVE-2025-14700EPSS 7%

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remot…

Mitigation only
Fix from $2,300 2025-12-17
Crafty Controller HIGH 7.1
CVE-2025-14701

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored X…

Fix: 4.6.2+
Fix from $1,950 2025-12-17
Crafty Controller MEDIUM 5.4
CVE-2025-5990

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacke…

Fix: 4.3.2 / 4.4.10+
Fix from $1,600 2025-06-15
Crafty Controller HIGH 7.5
CVE-2024-1064

A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denia…

Fix: after 4.2.2
Fix from $1,950 2024-02-03