Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cryptospike CRITICAL 9.1
CVE-2023-36649

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate…

No fix yet
Fix from $2,300 2023-12-12
Cryptospike HIGH 8.2
CVE-2023-36648

Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially …

No fix yet
Fix from $1,950 2023-12-12
Cryptospike HIGH 7.5
CVE-2023-36647

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate …

No fix yet
Fix from $1,950 2023-12-12
Cryptospike HIGH 7.2
CVE-2023-36650

A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the …

No fix yet
Fix from $1,950 2023-12-12
Cryptospike HIGH 7.2
CVE-2023-36651

Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the mo…

No fix yet
Fix from $1,950 2023-12-12
Cryptospike MEDIUM 6.5
CVE-2023-36654

Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host serv…

No fix yet
Fix from $1,600 2023-12-12
Cryptospike HIGH 8.8
CVE-2023-36646

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute p…

No fix yet
Fix from $1,950 2023-12-12
Cryptospike CRITICAL 9.8
CVE-2023-36655

The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login a…

No fix yet
Fix from $2,300 2023-12-06