Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2023-36649 Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate… Cryptospike No fix yet Fix from $2,3002023-12-12 HIGH 8.2 CVE-2023-36648 Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially … Cryptospike No fix yet Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-36647 A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate … Cryptospike No fix yet Fix from $1,9502023-12-12 HIGH 7.2 CVE-2023-36650 A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the … Cryptospike No fix yet Fix from $1,9502023-12-12 HIGH 7.2 CVE-2023-36651 Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the mo… Cryptospike No fix yet Fix from $1,9502023-12-12 MEDIUM 6.5 CVE-2023-36654 Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host serv… Cryptospike No fix yet Fix from $1,6002023-12-12 HIGH 8.8 CVE-2023-36646 Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute p… Cryptospike No fix yet Fix from $1,9502023-12-12 CRITICAL 9.8 CVE-2023-36655 The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login a… Cryptospike No fix yet Fix from $2,3002023-12-06