Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Software Acquisition Guide MEDIUM 6.1
CVE-2025-67634

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attack…

Fix: 2025-12-11+
Fix from $1,600 2025-12-12
Thorium HIGH 7.5
CVE-2025-35436

CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash…

Fix: after 1.1.2
Fix from $1,950 2025-09-17
Thorium CRITICAL 9.8
CVE-2025-35434

CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could …

Fix: 1.1.2+
Fix from $2,300 2025-09-17
Thorium HIGH 8.8
CVE-2025-35433

CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could s…

Patch available
Fix from $1,950 2025-09-17
Thorium HIGH 7.5
CVE-2025-35432

CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages …

Patch available
Fix from $1,950 2025-09-17
Thorium MEDIUM 6.5
CVE-2025-35430

CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated att…

Fix: 1.1.2+
Fix from $1,600 2025-09-17
Thorium MEDIUM 5.4
CVE-2025-35431

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such a…

Fix: 1.1.1+
Fix from $1,600 2025-09-17
Icsnpp Ethercat CRITICAL 9.8
CVE-2023-7243

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds writ…

Mitigation only
Fix from $2,300 2024-03-01
Icsnpp Ethercat CRITICAL 9.8
CVE-2023-7244

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds writ…

Mitigation only
Fix from $2,300 2024-03-01
Icsnpp Ethercat HIGH 8.2
CVE-2023-7242

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds read…

Mitigation only
Fix from $1,950 2024-03-01