VYPR
Vendor

Netflix

Products
16
CVEs
23
Across products
26
Status
Private

Products

16

Recent CVEs

23
View all 23 CVEs →
  • CVE-2020-9297CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker…

  • CVE-2020-9296CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.02

    Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message…

  • CVE-2024-7093CriAug 1, 2024
    risk 0.61cvss epss 0.01

    Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message…

  • CVE-2026-55166criJun 25, 2026
    risk 0.59cvss epss

    <!-- obsidian -->Lemur 1.9.0: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access…

  • CVE-2024-4701CriMay 14, 2024
    risk 0.59cvss 9.9epss 0.25

    A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

  • CVE-2025-26074CriJun 30, 2025
    risk 0.57cvss 9.8epss 0.01

    Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

  • CVE-2022-27177CriApr 1, 2022
    risk 0.57cvss 9.8epss 0.02

    A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

  • CVE-2020-9301HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within…

  • CVE-2024-5023CriMay 16, 2024
    risk 0.54cvss epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.

  • CVE-2024-9301HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a

  • CVE-2019-10028HigJun 21, 2019
    risk 0.49cvss 7.5epss 0.01

    Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.

  • CVE-2023-30797HigApr 19, 2023
    risk 0.42cvss 7.5epss 0.01

    Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.

  • CVE-2020-9300MedNov 9, 2020
    risk 0.42cvss 6.5epss 0.01

    The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted incident, and users able to view restricted incidents via the search feature. If your install has…

  • CVE-2015-7764HigAug 9, 2017
    risk 0.42cvss 7.5epss 0.02

    Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.

  • CVE-2021-28100MedMar 23, 2021
    risk 0.36cvss 5.5epss 0.00

    Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.

  • CVE-2020-9299MedNov 9, 2020
    risk 0.35cvss 5.4epss 0.01

    There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.

  • CVE-2017-7266MedMar 26, 2017
    risk 0.33cvss 6.1epss 0.01

    Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.

  • CVE-2021-28099MedMar 23, 2021
    risk 0.29cvss 4.4epss 0.00

    In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically…

  • CVE-2026-55165medJun 25, 2026
    risk 0.26cvss epss

    <!-- obsidian -->Lemur 1.9.0: JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap;…

  • CVE-2026-58138CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.07

    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API…