Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-62604
MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval of arbitrary user information.…
Metersphere
2.10.25+
CRITICAL 9.8
CVE-2025-53639
MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not proper…
Metersphere
3.6.5+
MEDIUM 6.1
CVE-2024-37161
MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores cross-site scripting vulnerab…
Metersphere
1.10.1+
MEDIUM 6.5
CVE-2024-32467
MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissions can view member informatio…
Metersphere
2.10.14+
CRITICAL 9.8
CVE-2023-41878
MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and perfor…
Metersphere
2.10.7+
HIGH 7.5
CVE-2023-38494
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not ha…
Metersphere
2.10.4+
CRITICAL 9.8
CVE-2023-37461
Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../…
Metersphere
2.10.3+
HIGH 8.8
CVE-2023-35937
Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This…
Metersphere
2.10.2+
MEDIUM 6.5
CVE-2023-32699
MeterSphere is an open source continuous testing platform. Version 2.9.1 and prior are vulnerable to denial of service. The `checkUserPassword` meth…
Metersphere
after 2.9.1
CRITICAL 9.8
CVE-2023-29944
Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snip…
Metersphere
No fix yet
MEDIUM 6.5
CVE-2023-25814
metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI …
Metersphere
2.7.1+
HIGH 7.5
CVE-2023-25573EPSS 52%
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/downl…
Metersphere
1.20.19+
HIGH 8.8
CVE-2022-46178
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. V…
Metersphere
2.5.1+
MEDIUM 6.1
CVE-2022-23544
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. V…
Metersphere
2.5.0+
HIGH 8.1
CVE-2022-23512
MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::de…
Metersphere
2.4.1+
CRITICAL 9.8
CVE-2021-45790
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where atta…
Metersphere
No fix yet
HIGH 8.8
CVE-2021-45788
Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter.
Metersphere
Patch available
MEDIUM 6.5
CVE-2021-45789
An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file downloa…
Metersphere
No fix yet