Skip to content
Noroxi

charm records

9 published records for vendor charm.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

9 records
  • Charm vulnerable to server-side request forgery (SSRF)

    CriticalCVSS 9.8No exploitEPSS 1%

    charm · charmMay 7, 2022

  • Wish has SCP Path Traversal that allows arbitrary file read/write

    CriticalCVSS 9.6No exploitEPSS 1%

    charm · wishMay 7, 2026

  • Soft Serve: SSRF via unvalidated LFS endpoint in repo import

    CriticalCVSS 9.1No exploitEPSS 0%

    charm · soft serveMar 7, 2026

  • Soft Serve has Critical Authentication Bypass

    HighCVSS 8.1No exploitEPSS 1%

    charm · soft serveJan 22, 2026

  • Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled

    HighCVSS 7.5No exploitEPSS 1%

    charm · soft serveOct 4, 2023

  • Soft Serve is vulnerable to SSRF through its Webhooks

    HighCVSS 7.6No exploitEPSS 0%

    charm · soft serveNov 10, 2025

  • Soft Serve: Authenticated repo import can clone server-local private repositories

    HighCVSS 7.1No exploitEPSS 0%

    charm · soft serveMar 24, 2026

  • Soft Serve allows path traversal attacks

    MediumCVSS 5.3No exploitEPSS 1%

    charm · soft serveJan 8, 2025

  • Soft Serve is missing an authorization check in LFS lock deletion

    MediumCVSS 5.4No exploitEPSS 0%

    charm · soft serveJan 8, 2026