VYPR

EVE-NG

by EVE-NG

CVEs (4)

  • CVE-2022-27903HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.

  • CVE-2022-31366HigOct 20, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.

  • CVE-2024-2391LowMar 12, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to…

  • CVE-2025-67442Dec 19, 2025
    risk 0.00cvss epss 0.00

    EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.