Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-47222 A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring … Signserver 7.3.1+ Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-47220 A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in… Signserver 7.3.1+ Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-47221 An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_… Signserver 7.3.1+ Fix from $1,6002025-11-13 HIGH 7.5 CVE-2024-42006 Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure. Aws Orchestrator 2.01+ Fix from $1,9502024-08-20 HIGH 7.5 CVE-2024-34458 Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure. Command Mitigation only Fix from $1,9502024-08-20 HIGH 8.2 CVE-2023-34196 In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentica… Ejbca 8.0.0+ Fix from $1,9502023-08-03 MEDIUM 5.4 CVE-2022-42954 Keyfactor EJBCA before 7.10.0 allows XSS. Kefactor Ejbca 7.10.0+ Fix from $1,6002022-11-17 MEDIUM 5.4 CVE-2022-39834 A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScri… Primekey Ejbca after 7.9.0.2 Fix from $1,6002022-11-17