Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Msm CRITICAL 9.8
CVE-2023-33282

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid sessio…

Fix: after 14.19.0.12476
Fix from $2,300 2023-06-07
Msm HIGH 8.8
CVE-2023-33284

Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute c…

Fix: after 14.19.0.12476
Fix from $1,950 2023-06-07
Msm MEDIUM 5.5
CVE-2023-33283

Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by usi…

Fix: after 14.19.0.12476
Fix from $1,600 2023-06-07
Marval Msm CRITICAL 9.8
CVE-2022-31887

Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, th…

No fix yet
Fix from $2,300 2022-06-28
Marval Msm MEDIUM 6.5
CVE-2022-31884

Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including hig…

No fix yet
Fix from $1,600 2022-06-28
Marval Msm CRITICAL 9.8
CVE-2022-31885EPSS 32%

Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

No fix yet
Fix from $2,300 2022-06-28
Marval Msm HIGH 8.8
CVE-2022-31883

Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys i…

Mitigation only
Fix from $1,950 2022-06-28
Marval Msm MEDIUM 6.5
CVE-2022-31886

Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.

No fix yet
Fix from $1,600 2022-06-28