Rdiffweb
Products
2- Rdiffweb44 CVEspypi
- 2 CVEs
Recent CVEs
46| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4724 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-4719 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-4314 | Cri | 0.57 | 9.8 | 0.01 | Dec 12, 2022 | Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. | ||
| CVE-2022-3362 | Cri | 0.57 | 9.8 | 0.01 | Nov 14, 2022 | Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-3363 | Cri | 0.57 | 9.8 | 0.01 | Oct 26, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. | ||
| CVE-2022-3327 | Cri | 0.57 | 9.8 | 0.01 | Oct 20, 2022 | Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. | ||
| CVE-2022-3439 | Cri | 0.57 | 9.8 | 0.01 | Oct 14, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-3457 | Cri | 0.57 | 9.8 | 0.00 | Oct 13, 2022 | Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5. | ||
| CVE-2022-3456 | Cri | 0.57 | 9.8 | 0.00 | Oct 13, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-3273 | Cri | 0.57 | 9.8 | 0.00 | Oct 6, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. | ||
| CVE-2022-3269 | Cri | 0.57 | 9.8 | 0.01 | Sep 23, 2022 | Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. | ||
| CVE-2025-67796 | Hig | 0.53 | 8.1 | 0.00 | May 4, 2026 | IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or… | ||
| CVE-2023-5289 | Hig | 0.50 | 8.8 | 0.01 | Sep 29, 2023 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4. | ||
| CVE-2022-3221 | Hig | 0.50 | 8.8 | 0.01 | Sep 15, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3. | ||
| CVE-2022-3179 | Hig | 0.50 | 8.8 | 0.01 | Sep 13, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2. | ||
| CVE-2022-3167 | Hig | 0.50 | 8.8 | 0.01 | Sep 8, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1. | ||
| CVE-2022-3389 | Hig | 0.42 | 7.5 | 0.01 | Oct 6, 2022 | Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. | ||
| CVE-2022-3371 | Hig | 0.42 | 7.5 | 0.01 | Sep 30, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. | ||
| CVE-2022-3364 | Hig | 0.42 | 7.5 | 0.01 | Sep 29, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. | ||
| CVE-2022-3298 | Hig | 0.42 | 7.5 | 0.01 | Sep 26, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.57cvss 9.8epss 0.01
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.57cvss 9.8epss 0.01
Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.01
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.
- risk 0.57cvss 9.8epss 0.01
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
- risk 0.57cvss 9.8epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.00
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
- risk 0.57cvss 9.8epss 0.00
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.00
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
- risk 0.57cvss 9.8epss 0.01
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
- risk 0.53cvss 8.1epss 0.00
IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or…
- risk 0.50cvss 8.8epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
- risk 0.50cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.
- risk 0.50cvss 8.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- risk 0.50cvss 8.8epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.
- risk 0.42cvss 7.5epss 0.01
Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.