Vendor CVEs
Rdiffweb
All CVEs
46 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4724 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-4719 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-4314 | Cri | 0.57 | 9.8 | 0.01 | Dec 12, 2022 | Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. | ||
| CVE-2022-3362 | Cri | 0.57 | 9.8 | 0.01 | Nov 14, 2022 | Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-3363 | Cri | 0.57 | 9.8 | 0.01 | Oct 26, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. | ||
| CVE-2022-3327 | Cri | 0.57 | 9.8 | 0.01 | Oct 20, 2022 | Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. | ||
| CVE-2022-3439 | Cri | 0.57 | 9.8 | 0.01 | Oct 14, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-3457 | Cri | 0.57 | 9.8 | 0.00 | Oct 13, 2022 | Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5. | ||
| CVE-2022-3456 | Cri | 0.57 | 9.8 | 0.00 | Oct 13, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-3273 | Cri | 0.57 | 9.8 | 0.00 | Oct 6, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. | ||
| CVE-2022-3269 | Cri | 0.57 | 9.8 | 0.01 | Sep 23, 2022 | Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. | ||
| CVE-2025-67796 | Hig | 0.53 | 8.1 | 0.00 | May 4, 2026 | IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or… | ||
| CVE-2023-5289 | Hig | 0.50 | 8.8 | 0.01 | Sep 29, 2023 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4. | ||
| CVE-2022-3221 | Hig | 0.50 | 8.8 | 0.01 | Sep 15, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3. | ||
| CVE-2022-3179 | Hig | 0.50 | 8.8 | 0.01 | Sep 13, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2. | ||
| CVE-2022-3167 | Hig | 0.50 | 8.8 | 0.01 | Sep 8, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1. | ||
| CVE-2022-3389 | Hig | 0.42 | 7.5 | 0.01 | Oct 6, 2022 | Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. | ||
| CVE-2022-3371 | Hig | 0.42 | 7.5 | 0.01 | Sep 30, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. | ||
| CVE-2022-3364 | Hig | 0.42 | 7.5 | 0.01 | Sep 29, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. | ||
| CVE-2022-3298 | Hig | 0.42 | 7.5 | 0.01 | Sep 26, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2022-3290 | Hig | 0.42 | 7.5 | 0.01 | Sep 26, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2022-3272 | Hig | 0.42 | 7.5 | 0.01 | Sep 26, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2022-3295 | Hig | 0.42 | 7.5 | 0.01 | Sep 26, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2022-3174 | Hig | 0.42 | 7.5 | 0.01 | Sep 13, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2. | ||
| CVE-2022-4722 | Hig | 0.40 | 7.2 | 0.01 | Dec 27, 2022 | Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2023-4138 | Med | 0.35 | 6.5 | 0.00 | Aug 3, 2023 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0. | ||
| CVE-2022-4723 | Med | 0.35 | 6.5 | 0.01 | Dec 27, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-4646 | Med | 0.35 | 6.5 | 0.00 | Dec 22, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4. | ||
| CVE-2022-4720 | Med | 0.33 | 6.1 | 0.00 | Dec 27, 2022 | Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-4644 | Med | 0.33 | 6.1 | 0.01 | Dec 22, 2022 | Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4. | ||
| CVE-2022-3438 | Med | 0.33 | 6.1 | 0.01 | Oct 10, 2022 | Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. | ||
| CVE-2022-4721 | Med | 0.28 | 5.4 | 0.00 | Dec 27, 2022 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-3376 | Med | 0.28 | 5.3 | 0.01 | Oct 6, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. | ||
| CVE-2022-3175 | Med | 0.28 | 5.3 | 0.01 | Sep 13, 2022 | Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2. | ||
| CVE-2022-3250 | Med | 0.27 | 5.3 | 0.00 | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6. | ||
| CVE-2022-3292 | Med | 0.23 | 4.6 | 0.01 | Sep 28, 2022 | Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2022-4018 | Med | 0.21 | 4.3 | 0.01 | Nov 16, 2022 | Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. | ||
| CVE-2022-3326 | Med | 0.21 | 4.3 | 0.01 | Sep 29, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9. | ||
| CVE-2022-3267 | Med | 0.21 | 4.3 | 0.00 | Sep 22, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6. | ||
| CVE-2022-3233 | Med | 0.21 | 4.3 | 0.00 | Sep 21, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6. | ||
| CVE-2022-3232 | Med | 0.21 | 4.3 | 0.00 | Sep 17, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5. | ||
| CVE-2022-3274 | Low | 0.16 | 3.5 | 0.00 | Sep 22, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7. | ||
| CVE-2022-3301 | Low | 0.09 | 2.4 | 0.01 | Sep 26, 2022 | Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2007-2747 | 0.03 | — | 0.04 | May 17, 2007 | Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI. | |||
| CVE-2022-3268 | Cri | 0.00 | 9.8 | 0.01 | Sep 22, 2022 | Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. | ||
| CVE-2022-3251 | Med | 0.00 | 5.3 | 0.01 | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2. |
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.57cvss 9.8epss 0.01
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.57cvss 9.8epss 0.01
Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.01
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.
- risk 0.57cvss 9.8epss 0.01
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
- risk 0.57cvss 9.8epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.00
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
- risk 0.57cvss 9.8epss 0.00
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.00
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
- risk 0.57cvss 9.8epss 0.01
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
- risk 0.53cvss 8.1epss 0.00
IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or…
- risk 0.50cvss 8.8epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
- risk 0.50cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.
- risk 0.50cvss 8.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- risk 0.50cvss 8.8epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.
- risk 0.42cvss 7.5epss 0.01
Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- risk 0.42cvss 7.5epss 0.01
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- risk 0.42cvss 7.5epss 0.01
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- risk 0.42cvss 7.5epss 0.01
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- risk 0.40cvss 7.2epss 0.01
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.35cvss 6.5epss 0.00
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
- risk 0.35cvss 6.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.
- risk 0.33cvss 6.1epss 0.00
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.33cvss 6.1epss 0.01
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.
- risk 0.33cvss 6.1epss 0.01
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
- risk 0.28cvss 5.4epss 0.00
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.28cvss 5.3epss 0.01
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
- risk 0.28cvss 5.3epss 0.01
Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- risk 0.27cvss 5.3epss 0.00
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
- risk 0.23cvss 4.6epss 0.01
Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- risk 0.21cvss 4.3epss 0.01
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
- risk 0.21cvss 4.3epss 0.01
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.
- risk 0.16cvss 3.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.
- risk 0.09cvss 2.4epss 0.01
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- CVE-2007-2747May 17, 2007risk 0.03cvss —epss 0.04
Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.
- risk 0.00cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
- risk 0.00cvss 5.3epss 0.01
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.