Vendor
Invenio
Products
6
CVEs
5
Across products
5
Status
Private
Products
6- 1 CVE
- 1 CVE
- 1 CVE
- invenio-app1 CVEpypi
- 1 CVE
- 0 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1020006 | Med | 0.40 | 6.1 | 0.01 | Jul 29, 2019 | invenio-app before 1.1.1 allows host header injection. | ||
| CVE-2019-1020019 | Med | 0.40 | 6.1 | 0.01 | Jul 29, 2019 | invenio-previewer before 1.0.0a12 allows XSS. | ||
| CVE-2021-43781 | Med | 0.35 | 6.4 | 0.01 | Dec 6, 2021 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable… | ||
| CVE-2019-1020003 | Med | 0.35 | 5.4 | 0.01 | Jul 29, 2019 | invenio-records before 1.2.2 allows XSS. | ||
| CVE-2019-1020005 | Med | 0.28 | 5.4 | 0.01 | Jul 29, 2019 | invenio-communities before 1.0.0a20 allows XSS. |
- risk 0.40cvss 6.1epss 0.01
invenio-app before 1.1.1 allows host header injection.
- risk 0.40cvss 6.1epss 0.01
invenio-previewer before 1.0.0a12 allows XSS.
- risk 0.35cvss 6.4epss 0.01
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable…
- risk 0.35cvss 5.4epss 0.01
invenio-records before 1.2.2 allows XSS.
- risk 0.28cvss 5.4epss 0.01
invenio-communities before 1.0.0a20 allows XSS.