Skip to content
Noroxi

CERN records

20 published records for vendor cern.

All records

20 records
  • Rucio SQL Injection in FilterEngine Oracle JSON Path via DID Search API

    CriticalCVSS 9.4No exploitEPSS 1%

    cern · rucioMay 6, 2026

  • ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code e

    HighCVSS 8.8No exploitEPSS 4%

    cern · rootNov 17, 2017

  • Rucio SQL injection in postgres_meta DID search path compromises PostgreSQL metadata database

    CriticalCVSS 9.0No exploitEPSS 1%

    cern · rucioMay 6, 2026

  • CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.

    HighCVSS 7.5No exploitEPSS 1%

    cern · indicoApr 7, 2021

  • Indico discloses local files resulting in Remote Code Execution through LaTeX injection

    HighCVSS 7.7No exploitEPSS 1%

    cern · indicoMar 23, 2026

  • A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted P

    HighCVSS 7.5Proof of conceptEPSS 1%

    cern · indicoJan 16, 2025

  • Indico has Server-Side Request Forgery (SSRF) in multiple places

    MediumCVSS 6.9No exploitEPSS 0%

    cern · indicoFeb 19, 2026

  • Indico missing access check in event series management API

    MediumCVSS 6.5No exploitEPSS 0%

    cern · indicoFeb 27, 2026

  • Indico has a Cross-Site-Scripting during account creation

    MediumCVSS 6.1No exploitEPSS 0%

    cern · indicoSep 4, 2024

  • Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    cern · rucioFeb 25, 2026

  • Indico vulnerable to user enumeration via API endpoint

    MediumCVSS 5.3Proof of conceptEPSS 1%

    cern · indicoJul 14, 2025

  • Cross-Site-Scripting via confirmation prompts

    MediumCVSS 5.4No exploitEPSS 1%

    cern · indicoJul 21, 2023

  • Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

    MediumCVSS 5.4No exploitEPSS 0%

    cern · rucioFeb 25, 2026

  • Rucio WebUI has Username Enumeration via Login Error Message

    MediumCVSS 5.3No exploitEPSS 0%

    cern · rucioFeb 25, 2026

  • Indico affected by Cross-Site-Scripting via material uploads

    MediumCVSS 5.4No exploitEPSS 0%

    cern · indicoFeb 19, 2026

  • Indico vulnerable to Cross-Site Scripting via LaTeX math code

    MediumCVSS 5.4No exploitEPSS 0%

    cern · indicoSep 10, 2025

  • Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

    MediumCVSS 4.8No exploitEPSS 0%

    cern · rucioFeb 25, 2026

  • Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

    MediumCVSS 4.8No exploitEPSS 0%

    cern · rucioFeb 25, 2026

  • Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

    MediumCVSS 4.8No exploitEPSS 0%

    cern · rucioFeb 25, 2026

  • Indico may disclose unauthorized user details access via legacy API

    MediumCVSS 4.3No exploitEPSS 0%

    cern · indicoSep 10, 2025