VYPR
Vendor

Rdiffweb

Products
2
CVEs
46
Across products
46
Status
Private

Products

2

Recent CVEs

46
View all 46 CVEs →
  • CVE-2022-4724CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4719CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4314CriDec 12, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.

  • CVE-2022-3362CriNov 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-3363CriOct 26, 2022
    risk 0.57cvss 9.8epss 0.01

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.

  • CVE-2022-3327CriOct 20, 2022
    risk 0.57cvss 9.8epss 0.01

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

  • CVE-2022-3439CriOct 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-3457CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.

  • CVE-2022-3456CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-3273CriOct 6, 2022
    risk 0.57cvss 9.8epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

  • CVE-2022-3269CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.01

    Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

  • CVE-2025-67796HigMay 4, 2026
    risk 0.53cvss 8.1epss 0.00

    IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or…

  • CVE-2023-5289HigSep 29, 2023
    risk 0.50cvss 8.8epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

  • CVE-2022-3221HigSep 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.

  • CVE-2022-3179HigSep 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.

  • CVE-2022-3167HigSep 8, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.

  • CVE-2022-3389HigOct 6, 2022
    risk 0.42cvss 7.5epss 0.01

    Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

  • CVE-2022-3371HigSep 30, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

  • CVE-2022-3364HigSep 29, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

  • CVE-2022-3298HigSep 26, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.