Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Signserver MEDIUM 6.5
CVE-2025-47222

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring …

Fix: 7.3.1+
Fix from $1,600 2025-11-13
Signserver MEDIUM 5.3
CVE-2025-47220

A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in…

Fix: 7.3.1+
Fix from $1,600 2025-11-13
Signserver MEDIUM 5.3
CVE-2025-47221

An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_…

Fix: 7.3.1+
Fix from $1,600 2025-11-13
Aws Orchestrator HIGH 7.5
CVE-2024-42006

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

Fix: 2.01+
Fix from $1,950 2024-08-20
Command HIGH 7.5
CVE-2024-34458

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.

Mitigation only
Fix from $1,950 2024-08-20
Ejbca HIGH 8.2
CVE-2023-34196

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentica…

Fix: 8.0.0+
Fix from $1,950 2023-08-03
Kefactor Ejbca MEDIUM 5.4
CVE-2022-42954

Keyfactor EJBCA before 7.10.0 allows XSS.

Fix: 7.10.0+
Fix from $1,600 2022-11-17
Primekey Ejbca MEDIUM 5.4
CVE-2022-39834

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScri…

Fix: after 7.9.0.2
Fix from $1,600 2022-11-17