VYPR

Vendor CVEs

Rdiffweb

All CVEs

46 total · sorted by risk
  • CVE-2022-4724CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4719CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4314CriDec 12, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.

  • CVE-2022-3362CriNov 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-3363CriOct 26, 2022
    risk 0.57cvss 9.8epss 0.01

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.

  • CVE-2022-3327CriOct 20, 2022
    risk 0.57cvss 9.8epss 0.01

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

  • CVE-2022-3439CriOct 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-3457CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.

  • CVE-2022-3456CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-3273CriOct 6, 2022
    risk 0.57cvss 9.8epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

  • CVE-2022-3269CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.01

    Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

  • CVE-2025-67796HigMay 4, 2026
    risk 0.53cvss 8.1epss 0.00

    IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or…

  • CVE-2023-5289HigSep 29, 2023
    risk 0.50cvss 8.8epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

  • CVE-2022-3221HigSep 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.

  • CVE-2022-3179HigSep 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.

  • CVE-2022-3167HigSep 8, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.

  • CVE-2022-3389HigOct 6, 2022
    risk 0.42cvss 7.5epss 0.01

    Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

  • CVE-2022-3371HigSep 30, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

  • CVE-2022-3364HigSep 29, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

  • CVE-2022-3298HigSep 26, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

  • CVE-2022-3290HigSep 26, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

  • CVE-2022-3272HigSep 26, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

  • CVE-2022-3295HigSep 26, 2022
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

  • CVE-2022-3174HigSep 13, 2022
    risk 0.42cvss 7.5epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2.

  • CVE-2022-4722HigDec 27, 2022
    risk 0.40cvss 7.2epss 0.01

    Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2023-4138MedAug 3, 2023
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.

  • CVE-2022-4723MedDec 27, 2022
    risk 0.35cvss 6.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4646MedDec 22, 2022
    risk 0.35cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.

  • CVE-2022-4720MedDec 27, 2022
    risk 0.33cvss 6.1epss 0.00

    Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4644MedDec 22, 2022
    risk 0.33cvss 6.1epss 0.01

    Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.

  • CVE-2022-3438MedOct 10, 2022
    risk 0.33cvss 6.1epss 0.01

    Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

  • CVE-2022-4721MedDec 27, 2022
    risk 0.28cvss 5.4epss 0.00

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-3376MedOct 6, 2022
    risk 0.28cvss 5.3epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

  • CVE-2022-3175MedSep 13, 2022
    risk 0.28cvss 5.3epss 0.01

    Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.

  • CVE-2022-3250MedSep 21, 2022
    risk 0.27cvss 5.3epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.

  • CVE-2022-3292MedSep 28, 2022
    risk 0.23cvss 4.6epss 0.01

    Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.

  • CVE-2022-4018MedNov 16, 2022
    risk 0.21cvss 4.3epss 0.01

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

  • CVE-2022-3326MedSep 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.

  • CVE-2022-3267MedSep 22, 2022
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.

  • CVE-2022-3233MedSep 21, 2022
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.

  • CVE-2022-3232MedSep 17, 2022
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.

  • CVE-2022-3274LowSep 22, 2022
    risk 0.16cvss 3.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.

  • CVE-2022-3301LowSep 26, 2022
    risk 0.09cvss 2.4epss 0.01

    Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.

  • CVE-2007-2747May 17, 2007
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.

  • CVE-2022-3268CriSep 22, 2022
    risk 0.00cvss 9.8epss 0.01

    Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

  • CVE-2022-3251MedSep 21, 2022
    risk 0.00cvss 5.3epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.