Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Business Workflow
MEDIUM 6.5
CVE-2020-26175
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile info…
Fix: 1.18.1+
Fix from $1,600
2020-12-18
Business Workflow
MEDIUM 5.3
CVE-2020-26178
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.
Fix: 1.18.1+
Fix from $1,600
2020-12-18
Business Workflow
HIGH 8.8
CVE-2020-26174
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this …
Fix: 1.18.1+
Fix from $1,950
2020-12-18
Business Workflow
MEDIUM 6.5
CVE-2020-26172
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is act…
Fix: 1.18.1+
Fix from $1,600
2020-12-18