Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2022-40606
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…
Caldera
4.1.0+
MEDIUM 6.1
CVE-2022-40605
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…
Caldera
4.1.0+
MEDIUM 5.4
CVE-2022-41139
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on …
Caldera
4.1.0+
HIGH 7.5
CVE-2022-31004
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secre…
Cve Services
No fix yet
HIGH 7.2
CVE-2021-46561
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational ad…
Cve Services
Patch available
HIGH 8.8
CVE-2021-42559
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c…
Caldera
after 2.8.1
MEDIUM 6.1
CVE-2021-42558
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated…
Caldera
after 2.8.1
HIGH 8.8
CVE-2021-42560
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum…
Caldera
No fix yet
HIGH 8.8
CVE-2021-42561EPSS 20%
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th…
Caldera
after 2.8.1
HIGH 8.1
CVE-2021-42562
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modi…
Caldera
after 2.8.1
HIGH 8.8
CVE-2020-19907
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
Caldera
after 2.3.1
MEDIUM 5.4
CVE-2020-14462
CALDERA 2.7.0 allows XSS via the Operation Name box.
Caldera
No fix yet
MEDIUM 5.3
CVE-2020-10807
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
Caldera
2.6.5+
HIGH 10.0
CVE-2008-4704
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in …
Sezhoo
No fix yet