Vendor
Oxide
Products
4
CVEs
5
Across products
7
Status
Private
Products
4- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-50913 | Cri | 0.59 | 9.1 | 0.00 | Dec 5, 2024 | Oxide control plane software before 5 allows SSRF. | ||
| CVE-2024-55582 | Med | 0.37 | 5.7 | 0.00 | Dec 9, 2024 | Oxide before 6 has unencrypted Control Plane datastores. | ||
| CVE-2025-66432 | Med | 0.33 | 5.0 | 0.00 | Nov 30, 2025 | In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date. | ||
| CVE-2016-1586 | Low | 0.00 | 1.8 | 0.01 | Apr 22, 2019 | A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3. | ||
| CVE-2015-1317 | 0.00 | — | 0.03 | Apr 8, 2015 | Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists. |
- risk 0.59cvss 9.1epss 0.00
Oxide control plane software before 5 allows SSRF.
- risk 0.37cvss 5.7epss 0.00
Oxide before 6 has unencrypted Control Plane datastores.
- risk 0.33cvss 5.0epss 0.00
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
- risk 0.00cvss 1.8epss 0.01
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
- CVE-2015-1317Apr 8, 2015risk 0.00cvss —epss 0.03
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.