Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Plextrac CRITICAL 9.8
CVE-2024-12687

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue a…

Fix: 2.8.1+
Fix from $2,300 2024-12-16
Plextrac CRITICAL 9.8
CVE-2024-11838

External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API endpoint.This issue af…

Fix: 2.8.1+
Fix from $2,300 2024-12-13
Plextrac HIGH 7.5
CVE-2024-11839

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue aff…

Fix: 2.8.1+
Fix from $1,950 2024-12-13
Plextrac CRITICAL 9.8
CVE-2024-11837

Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac  allows N1QL Injection.This issue af…

Fix: 2.8.1+
Fix from $2,300 2024-12-13
Plextrac CRITICAL 9.1
CVE-2024-11833

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affe…

Fix: 2.8.1+
Fix from $2,300 2024-12-13
Plextrac CRITICAL 9.1
CVE-2024-11834

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affe…

Fix: 2.8.1+
Fix from $2,300 2024-12-13
Plextrac HIGH 7.5
CVE-2024-11835

Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Fix: 2.8.1+
Fix from $1,950 2024-12-13
Plextrac HIGH 7.5
CVE-2024-11836

Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 …

Fix: 2.8.1+
Fix from $1,950 2024-12-13
Plextrac HIGH 8.8
CVE-2022-37144

The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in pos…

Fix: 1.17.0+
Fix from $1,950 2022-09-08
Plextrac HIGH 7.5
CVE-2022-37145

The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authent…

Fix: 1.17.0+
Fix from $1,950 2022-09-08
Plextrac MEDIUM 5.3
CVE-2022-37146

The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured …

Fix: 1.28.0+
Fix from $1,600 2022-09-08