Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-40606 MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20… Caldera 4.1.0+ Fix from $1,6002022-10-17 MEDIUM 6.1 CVE-2022-40605 MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20… Caldera 4.1.0+ Fix from $1,6002022-10-17 MEDIUM 5.4 CVE-2022-41139 MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on … Caldera 4.1.0+ Fix from $1,6002022-10-17 HIGH 7.5 CVE-2022-31004 CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secre… Cve Services No fix yet Fix from $1,9502022-06-02 HIGH 7.2 CVE-2021-46561 controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational ad… Cve Services Patch available Fix from $1,9502022-01-26 HIGH 8.8 CVE-2021-42559 An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c… Caldera after 2.8.1 Fix from $1,9502022-01-12 MEDIUM 6.1 CVE-2021-42558 An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated… Caldera after 2.8.1 Fix from $1,6002022-01-12 HIGH 8.8 CVE-2021-42560 An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum… Caldera No fix yet Fix from $1,9502022-01-12 HIGH 8.8 CVE-2021-42561EPSS 20% An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th… Caldera after 2.8.1 Fix from $1,9502022-01-12 HIGH 8.1 CVE-2021-42562 An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modi… Caldera after 2.8.1 Fix from $1,9502022-01-12 HIGH 8.8 CVE-2020-19907 A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service. Caldera after 2.3.1 Fix from $1,9502021-07-12 MEDIUM 5.4 CVE-2020-14462 CALDERA 2.7.0 allows XSS via the Operation Name box. Caldera No fix yet Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2020-10807 auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header. Caldera 2.6.5+ Fix from $1,6002020-03-22 HIGH 10.0 CVE-2008-4704 PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in … Sezhoo No fix yet Fix from $1,9502008-10-23