Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tgstation Server HIGH 8.8
CVE-2025-21611

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd i…

Fix: 6.12.3+
Fix from $1,950 2025-01-06
Tgstation Server CRITICAL 9.9
CVE-2024-41799

tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege cou…

Fix: 6.8.0+
Fix from $2,300 2024-07-29
Tgstation Server MEDIUM 5.3
CVE-2023-34243

TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attack…

Fix: 5.12.5+
Fix from $1,600 2023-06-08
Tgstation Server HIGH 7.5
CVE-2023-33198

tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache can possibly be poisoned by a …

Fix: 5.12.2+
Fix from $1,950 2023-05-30
Tgstation Server MEDIUM 6.5
CVE-2023-32687

tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bo…

Fix: 5.12.1+
Fix from $1,600 2023-05-29
Tgstation Server HIGH 7.7
CVE-2020-16136

In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible b…

Mitigation only
Fix from $1,950 2020-07-31
Tgstation Server CRITICAL 9.8
CVE-2018-17107

In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subsequent logins to succeed with a…

Fix: 3.2.5.0+
Fix from $2,300 2018-09-24