Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rucio HIGH 8.8
CVE-2026-29090

### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.crea…

Fix: 35.8.5 / 38.5.5+
Fix from $1,950 2026-05-06
Rucio HIGH 8.8
CVE-2026-29080

A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend …

Fix: 35.8.5 / 38.5.5+
Fix from $1,950 2026-05-06
Indico HIGH 8.8
CVE-2026-33046

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to …

Fix: 3.3.12+
Fix from $1,950 2026-03-23
Indico MEDIUM 6.5
CVE-2026-28352

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API…

Fix: 3.3.11+
Fix from $1,600 2026-02-27
Rucio MEDIUM 6.1
CVE-2026-25136

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie…

Fix: 35.8.3 / 38.5.4+
Fix from $1,600 2026-02-25
Rucio MEDIUM 5.4
CVE-2026-25733

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie…

Fix: 35.8.3 / 38.5.4+
Fix from $1,600 2026-02-25
Rucio MEDIUM 5.3
CVE-2026-25138

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie…

Fix: 35.8.3 / 38.5.4+
Fix from $1,600 2026-02-25
Indico MEDIUM 5.4
CVE-2026-25739

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnera…

Fix: 3.3.10+
Fix from $1,600 2026-02-19
Indico MEDIUM 5.4
CVE-2025-59035

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a C…

Fix: 3.3.8+
Fix from $1,600 2025-09-10
Indico MEDIUM 6.5
CVE-2025-53640

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to…

Fix: 3.3.7+
Fix from $1,600 2025-07-14
Indico HIGH 7.5
CVE-2024-50633

A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST reque…

Fix: after 3.3.2
Fix from $1,950 2025-01-16
Indico MEDIUM 6.1
CVE-2024-45399

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, co…

Fix: 3.3.4+
Fix from $1,600 2024-09-04
Indico MEDIUM 5.4
CVE-2023-37901

Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts co…

Fix: 3.2.6+
Fix from $1,600 2023-07-21
Indico HIGH 7.5
CVE-2021-30185

CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.

Fix: 2.3.4+
Fix from $1,950 2021-04-07
Root HIGH 8.8
CVE-2017-1000203

ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution

Fix: after 6.9.03
Fix from $1,950 2017-11-17