VYPR
Vendor

Oxide

Products
4
CVEs
5
Across products
7
Status
Private

Products

4

Recent CVEs

5
  • CVE-2023-50913CriDec 5, 2024
    risk 0.59cvss 9.1epss 0.00

    Oxide control plane software before 5 allows SSRF.

  • CVE-2024-55582MedDec 9, 2024
    risk 0.37cvss 5.7epss 0.00

    Oxide before 6 has unencrypted Control Plane datastores.

  • CVE-2025-66432MedNov 30, 2025
    risk 0.33cvss 5.0epss 0.00

    In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

  • CVE-2016-1586LowApr 22, 2019
    risk 0.00cvss 1.8epss 0.01

    A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

  • CVE-2015-1317Apr 8, 2015
    risk 0.00cvss epss 0.03

    Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.