Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cfengine HIGH 7.3
CVE-2026-24712

Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

Fix: 3.21.8 / 3.24.3+
Fix from $1,950 2026-05-14
Cfengine MEDIUM 6.1
CVE-2026-24710

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.

Fix: 3.21.8 / 3.24.3+
Fix from $1,600 2026-05-14
Cfengine MEDIUM 5.3
CVE-2026-24711

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.

Fix: 3.21.8 / 3.24.3+
Fix from $1,600 2026-05-14
Cfengine HIGH 7.5
CVE-2023-45684

Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.…

Fix: 3.18.6 / 3.21.3+
Fix from $1,950 2023-11-14
Cfengine MEDIUM 6.5
CVE-2023-26560

Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary fi…

Fix: 3.21.1+
Fix from $1,600 2023-04-26
Mender CRITICAL 9.8
CVE-2022-29556

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several…

Mitigation only
Fix from $2,300 2022-04-28
Mender HIGH 8.8
CVE-2022-29555

The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.

Fix: 3.2.2+
Fix from $1,950 2022-04-28
Cfengine MEDIUM 5.5
CVE-2021-44216

Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access t…

Fix: 3.15.5 / 3.18.1+
Fix from $1,600 2022-03-10
Cfengine MEDIUM 5.5
CVE-2021-44215

Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.

Fix: 3.15.5 / 3.18.1+
Fix from $1,600 2022-03-10
Cfengine MEDIUM 5.5
CVE-2021-38379

The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.

Fix: after 3.18.0
Fix from $1,600 2021-10-27
Cfengine MEDIUM 6.5
CVE-2021-36756

CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.

Fix: after 3.15.4
Fix from $1,600 2021-10-27
Useradm HIGH 7.5
CVE-2021-35342

The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1)…

Mitigation only
Fix from $1,950 2021-08-27
Cfengine MEDIUM 6.1
CVE-2019-19394

Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and…

Fix: 3.10.7 / 3.12.3+
Fix from $1,600 2020-04-16