Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Caldera MEDIUM 6.1
CVE-2022-40606

MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…

Fix: 4.1.0+
Fix from $1,600 2022-10-17
Caldera MEDIUM 6.1
CVE-2022-40605

MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…

Fix: 4.1.0+
Fix from $1,600 2022-10-17
Caldera MEDIUM 5.4
CVE-2022-41139

MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on …

Fix: 4.1.0+
Fix from $1,600 2022-10-17
Cve Services HIGH 7.5
CVE-2022-31004

CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secre…

No fix yet
Fix from $1,950 2022-06-02
Cve Services HIGH 7.2
CVE-2021-46561

controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational ad…

Patch available
Fix from $1,950 2022-01-26
Caldera HIGH 8.8
CVE-2021-42559

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c…

Fix: after 2.8.1
Fix from $1,950 2022-01-12
Caldera MEDIUM 6.1
CVE-2021-42558

An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated…

Fix: after 2.8.1
Fix from $1,600 2022-01-12
Caldera HIGH 8.8
CVE-2021-42560

An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum…

No fix yet
Fix from $1,950 2022-01-12
Caldera HIGH 8.8
CVE-2021-42561EPSS 20%

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th…

Fix: after 2.8.1
Fix from $1,950 2022-01-12
Caldera HIGH 8.1
CVE-2021-42562

An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modi…

Fix: after 2.8.1
Fix from $1,950 2022-01-12
Caldera HIGH 8.8
CVE-2020-19907

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

Fix: after 2.3.1
Fix from $1,950 2021-07-12
Caldera MEDIUM 5.4
CVE-2020-14462

CALDERA 2.7.0 allows XSS via the Operation Name box.

No fix yet
Fix from $1,600 2020-06-19
Caldera MEDIUM 5.3
CVE-2020-10807

auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.

Fix: 2.6.5+
Fix from $1,600 2020-03-22
Sezhoo HIGH 10.0
CVE-2008-4704

PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2008-10-23