Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-9301 A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a E2nest 2024-09-05+ Fix from $1,9502024-09-27 HIGH 7.5 CVE-2023-40171 Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error me… Dispatch 20230817+ Fix from $1,9502023-08-17 HIGH 7.5 CVE-2023-30797 Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow … Lemur 1.3.2+ Fix from $1,9502023-04-19 CRITICAL 9.8 CVE-2022-27177 A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Consoleme 1.2.2+ Fix from $2,3002022-04-01 MEDIUM 5.5 CVE-2021-28100 Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read an… Priam Mitigation only Fix from $1,6002021-03-23 HIGH 7.5 CVE-2020-2322 Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permis… Chaos Monkey after 0.3 Fix from $1,9502020-12-03 MEDIUM 5.3 CVE-2020-2323 Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission t… Chaos Monkey after 0.4 Fix from $1,6002020-12-03 MEDIUM 6.5 CVE-2020-9300 The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a … Dispatch 20201106+ Fix from $1,6002020-11-09 MEDIUM 5.4 CVE-2020-9299 There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, I… Dispatch 20201106+ Fix from $1,6002020-11-09 CRITICAL 9.8 CVE-2020-9297 Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom co… Titus after 0.1.0 Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2020-9296 Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different t… Conductor after 2.25.3 Fix from $2,3002020-06-16 HIGH 7.5 CVE-2019-10028 Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019. Dial Reference 6-18-2019+ Fix from $1,9502019-06-21 HIGH 7.5 CVE-2015-7764 Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode. Lemur Mitigation only Fix from $1,9502017-08-09 MEDIUM 6.1 CVE-2017-7266 Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain … Security Monkey after 0.7.0 Fix from $1,6002017-03-26