ORCA
by ORCA
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-4245 | Hig | 0.47 | 7.3 | 0.01 | Dec 11, 2019 | Orca has arbitrary code execution due to insecure Python module load | ||
| CVE-2018-0643 | Med | 0.43 | 6.6 | 0.01 | Sep 7, 2018 | Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. | ||
| CVE-2026-25599 | Med | 0.41 | 6.3 | 0.00 | Jun 1, 2026 | Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca… | ||
| CVE-2021-35967 | Med | 0.35 | 5.3 | 0.01 | Jul 19, 2021 | The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in. |
- risk 0.47cvss 7.3epss 0.01
Orca has arbitrary code execution due to insecure Python module load
- risk 0.43cvss 6.6epss 0.01
Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
- risk 0.41cvss 6.3epss 0.00
Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca…
- risk 0.35cvss 5.3epss 0.01
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.