İçeriğe atla
Noroxi

CERN kayıtları

cern üreticisine ait 20 yayımlanmış kayıt.

Tüm kayıtlar

20 kayıt
  • CVE-2026-29080
    37İzleyin

    Rucio SQL Injection in FilterEngine Oracle JSON Path via DID Search API

    KritikCVSS 9,4İstismar yokEPSS %1

    cern · rucio6 May 2026

  • ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code e

    YüksekCVSS 8,8İstismar yokEPSS %4

    cern · root17 Kas 2017

  • CVE-2026-29090
    36İzleyin

    Rucio SQL injection in postgres_meta DID search path compromises PostgreSQL metadata database

    KritikCVSS 9,0İstismar yokEPSS %1

    cern · rucio6 May 2026

  • CVE-2021-30185
    30İzleyin

    CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.

    YüksekCVSS 7,5İstismar yokEPSS %1

    cern · indico7 Nis 2021

  • CVE-2026-33046
    30İzleyin

    Indico discloses local files resulting in Remote Code Execution through LaTeX injection

    YüksekCVSS 7,7İstismar yokEPSS %1

    cern · indico23 Mar 2026

  • CVE-2024-50633
    30İzleyin

    A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted P

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    cern · indico16 Oca 2025

  • CVE-2026-25738
    27İzleyin

    Indico has Server-Side Request Forgery (SSRF) in multiple places

    OrtaCVSS 6,9İstismar yokEPSS %0

    cern · indico19 Şub 2026

  • CVE-2026-28352
    26İzleyin

    Indico missing access check in event series management API

    OrtaCVSS 6,5İstismar yokEPSS %0

    cern · indico27 Şub 2026

  • CVE-2024-45399
    24İzleyin

    Indico has a Cross-Site-Scripting during account creation

    OrtaCVSS 6,1İstismar yokEPSS %0

    cern · indico4 Eyl 2024

  • CVE-2026-25136
    24İzleyin

    Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %0

    cern · rucio25 Şub 2026

  • CVE-2025-53640
    21İzleyin

    Indico vulnerable to user enumeration via API endpoint

    OrtaCVSS 5,3Kavram kanıtıEPSS %1

    cern · indico14 Tem 2025

  • CVE-2023-37901
    21İzleyin

    Cross-Site-Scripting via confirmation prompts

    OrtaCVSS 5,4İstismar yokEPSS %1

    cern · indico21 Tem 2023

  • CVE-2026-25733
    21İzleyin

    Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

    OrtaCVSS 5,4İstismar yokEPSS %0

    cern · rucio25 Şub 2026

  • CVE-2026-25138
    21İzleyin

    Rucio WebUI has Username Enumeration via Login Error Message

    OrtaCVSS 5,3İstismar yokEPSS %0

    cern · rucio25 Şub 2026

  • CVE-2026-25739
    21İzleyin

    Indico affected by Cross-Site-Scripting via material uploads

    OrtaCVSS 5,4İstismar yokEPSS %0

    cern · indico19 Şub 2026

  • CVE-2025-59035
    21İzleyin

    Indico vulnerable to Cross-Site Scripting via LaTeX math code

    OrtaCVSS 5,4İstismar yokEPSS %0

    cern · indico10 Eyl 2025

  • CVE-2026-25735
    19İzleyin

    Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

    OrtaCVSS 4,8İstismar yokEPSS %0

    cern · rucio25 Şub 2026

  • CVE-2026-25736
    19İzleyin

    Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

    OrtaCVSS 4,8İstismar yokEPSS %0

    cern · rucio25 Şub 2026

  • CVE-2026-25734
    19İzleyin

    Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

    OrtaCVSS 4,8İstismar yokEPSS %0

    cern · rucio25 Şub 2026

  • CVE-2025-59034
    17İzleyin

    Indico may disclose unauthorized user details access via legacy API

    OrtaCVSS 4,3İstismar yokEPSS %0

    cern · indico10 Eyl 2025