| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24837 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-24488 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-20020 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2026-18725 | mod | 0.41 | 6.3 | — | Aug 12, 2026 | open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling | ||
| CVE-2026-18724 | mod | 0.49 | 7.6 | — | Aug 12, 2026 | open-iscsi: open-iscsi: Stack buffer overflow in idbm record parsing | ||
| CVE-2026-73432 | Med | 0.26 | — | 0.00 | Aug 12, 2026 | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL syntax before being stored, while the synchronization worker later dereferenced… | ||
| CVE-2026-73431 | Hig | 0.50 | — | 0.00 | Aug 12, 2026 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although the token signature and age were… | ||
| CVE-2026-73405 | Med | 0.27 | — | 0.01 | Aug 12, 2026 | An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/ endpoint. The token_required decorator used by the Pub/Sub interface authenticated… | ||
| CVE-2026-73374 | Med | 0.33 | — | 0.01 | Aug 12, 2026 | A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from containers.cna.references[].tags[] were directly interpolated into HTML… | ||
| CVE-2026-73291 | Hig | 0.39 | 7.1 | 0.00 | Aug 12, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET… | ||
| CVE-2026-73290 | Med | 0.27 | 5.3 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policy_allowed path… | ||
| CVE-2026-73289 | Hig | 0.46 | 8.1 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using… | ||
| CVE-2026-73288 | Med | 0.33 | — | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound,… | ||
| CVE-2026-73287 | Med | 0.28 | 5.4 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated… | ||
| CVE-2026-73286 | Hig | 0.46 | 8.1 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:… | ||
| CVE-2026-73285 | Hig | 0.42 | 7.5 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,… | ||
| CVE-2026-73284 | Hig | 0.50 | 8.8 | 0.01 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and… | ||
| CVE-2026-73265 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to… | ||
| CVE-2026-73264 | Hig | 0.42 | 7.6 | 0.00 | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST… | ||
| CVE-2026-73263 | Cri | 0.57 | 9.9 | 0.01 | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in… | ||
| CVE-2026-73262 | Med | 0.28 | 5.4 | 0.00 | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who… | ||
| CVE-2026-68760 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may bypass authentication under specific cache conditions. | ||
| CVE-2026-68757 | Hig | 0.49 | 7.5 | 0.00 | Aug 12, 2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. | ||
| CVE-2026-68756 | Med | 0.43 | 6.6 | 0.00 | Aug 12, 2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | ||
| CVE-2026-68755 | — | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | A bundle writer may create misleading release promotion information under specific conditions. | |
| CVE-2026-68754 | Med | 0.42 | 6.5 | 0.00 | Aug 12, 2026 | A repository publisher without delete permission may modify protected package content under specific conditions. | ||
| CVE-2026-68753 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | ||
| CVE-2026-68752 | Hig | 0.47 | 7.2 | 0.00 | Aug 12, 2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. | ||
| CVE-2026-67287 | Med | 0.41 | — | 0.00 | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | ||
| CVE-2026-67286 | Med | 0.41 | — | 0.01 | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | ||
| CVE-2026-66382 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | ||
| CVE-2026-66381 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | ||
| CVE-2026-66380 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | ||
| CVE-2026-66379 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user may view private Puppet module metadata without repository read access. | ||
| CVE-2026-66378 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | ||
| CVE-2026-66377 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted repository information under specific conditions. | ||
| CVE-2026-66376 | — | Med | 0.27 | 4.2 | 0.00 | Aug 12, 2026 | Credentials for a deleted user may remain valid for a short period under specific conditions. | |
| CVE-2026-66375 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | ||
| CVE-2026-50561 | Cri | 0.61 | 9.4 | 0.01 | Aug 12, 2026 | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the… | ||
| CVE-2026-49349 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2026 | regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict… | ||
| CVE-2026-49262 | Low | 0.20 | 3.0 | 0.00 | Aug 12, 2026 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL… | ||
| CVE-2026-47234 | Med | 0.22 | 4.4 | 0.00 | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session… | ||
| CVE-2026-47233 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory… | ||
| CVE-2026-18171 | Med | 0.37 | — | 0.00 | Aug 12, 2026 | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path,… | ||
| CVE-2026-14479 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2026 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT… | ||
| CVE-2026-14478 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. | ||
| CVE-2025-59324 | Cri | 0.59 | 9.1 | 0.00 | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | ||
| CVE-2025-59323 | Hig | 0.55 | 8.4 | 0.00 | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for… | ||
| CVE-2025-59322 | Hig | 0.49 | 7.5 | 0.00 | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | ||
| CVE-2025-59321 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform. |
- CVE-2025-24837Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-24488Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-20020Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- risk 0.41cvss 6.3epss —
open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling
- risk 0.49cvss 7.6epss —
open-iscsi: open-iscsi: Stack buffer overflow in idbm record parsing
- risk 0.26cvss —epss 0.00
Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL syntax before being stored, while the synchronization worker later dereferenced…
- risk 0.50cvss —epss 0.00
Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although the token signature and age were…
- risk 0.27cvss —epss 0.01
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/ endpoint. The token_required decorator used by the Pub/Sub interface authenticated…
- risk 0.33cvss —epss 0.01
A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from containers.cna.references[].tags[] were directly interpolated into HTML…
- risk 0.39cvss 7.1epss 0.00
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET…
- risk 0.27cvss 5.3epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policy_allowed path…
- risk 0.46cvss 8.1epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using…
- risk 0.33cvss —epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound,…
- risk 0.28cvss 5.4epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated…
- risk 0.46cvss 8.1epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:…
- risk 0.42cvss 7.5epss 0.00
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,…
- risk 0.50cvss 8.8epss 0.01
RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and…
- risk 0.35cvss 6.5epss 0.00
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to…
- risk 0.42cvss 7.6epss 0.00
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST…
- risk 0.57cvss 9.9epss 0.01
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in…
- risk 0.28cvss 5.4epss 0.00
Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who…
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may bypass authentication under specific cache conditions.
- risk 0.49cvss 7.5epss 0.00
A user with access to a valid SAML response may impersonate another user under specific conditions.
- risk 0.43cvss 6.6epss 0.00
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
- risk 0.28cvss 4.3epss 0.00
A bundle writer may create misleading release promotion information under specific conditions.
- risk 0.42cvss 6.5epss 0.00
A repository publisher without delete permission may modify protected package content under specific conditions.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
- risk 0.47cvss 7.2epss 0.00
A Project Resource Manager may gain broader administrative privileges under specific conditions.
- risk 0.41cvss —epss 0.00
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.
- risk 0.41cvss —epss 0.01
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.
- risk 0.28cvss 4.3epss 0.00
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
- risk 0.34cvss 5.3epss 0.00
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
- risk 0.28cvss 4.3epss 0.00
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
- risk 0.28cvss 4.3epss 0.00
An authenticated user may view private Puppet module metadata without repository read access.
- risk 0.28cvss 4.3epss 0.00
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may access restricted repository information under specific conditions.
- risk 0.27cvss 4.2epss 0.00
Credentials for a deleted user may remain valid for a short period under specific conditions.
- risk 0.53cvss 8.1epss 0.00
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
- risk 0.61cvss 9.4epss 0.01
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the…
- risk 0.44cvss 6.8epss 0.00
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict…
- risk 0.20cvss 3.0epss 0.00
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL…
- risk 0.22cvss 4.4epss 0.00
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session…
- risk 0.35cvss 6.5epss 0.00
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory…
- risk 0.37cvss —epss 0.00
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path,…
- risk 0.36cvss 5.5epss 0.00
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT…
- risk 0.51cvss 7.8epss 0.00
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
- risk 0.59cvss 9.1epss 0.00
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
- risk 0.55cvss 8.4epss 0.00
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for…
- risk 0.49cvss 7.5epss 0.00
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
- risk 0.64cvss 9.8epss 0.01
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.