charm records
9 published records for vendor charm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-289 Authentication Bypass by Alternate Name1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-29180No exploit | Charm vulnerable to server-side request forgery (SSRF)charm · charm · CWE-918 | Critical9.8 | — | 0.8% | May 7, 2022 |
38Monitor | CVE-2026-41589No exploit | Wish has SCP Path Traversal that allows arbitrary file read/writecharm · wish · CWE-22 | Critical9.6 | — | 0.5% | May 7, 2026 |
36Monitor | CVE-2026-30832No exploit | Soft Serve: SSRF via unvalidated LFS endpoint in repo importcharm · soft serve · CWE-918 | Critical9.1 | — | 0.4% | Mar 7, 2026 |
32Monitor | CVE-2026-24058No exploit | Soft Serve has Critical Authentication Bypasscharm · soft serve · CWE-289 | High8.1 | — | 0.6% | Jan 22, 2026 |
30Monitor | CVE-2023-43809No exploit | Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabledcharm · soft serve · CWE-287 | High7.5 | — | 0.9% | Oct 4, 2023 |
30Monitor | CVE-2025-64522No exploit | Soft Serve is vulnerable to SSRF through its Webhookscharm · soft serve · CWE-918 | High7.6 | — | 0.3% | Nov 10, 2025 |
28Monitor | CVE-2026-33353No exploit | Soft Serve: Authenticated repo import can clone server-local private repositoriescharm · soft serve · CWE-200 | High7.1 | — | 0.4% | Mar 24, 2026 |
21Monitor | CVE-2025-22130No exploit | Soft Serve allows path traversal attackscharm · soft serve · CWE-22 | Medium5.3 | — | 0.7% | Jan 8, 2025 |
21Monitor | CVE-2026-22253No exploit | Soft Serve is missing an authorization check in LFS lock deletioncharm · soft serve · CWE-863 | Medium5.4 | — | 0.3% | Jan 8, 2026 |
- CVE-2022-2918039Monitor
Charm vulnerable to server-side request forgery (SSRF)
CriticalCVSS 9.8No exploitEPSS 1%charm · charmMay 7, 2022
- CVE-2026-4158938Monitor
Wish has SCP Path Traversal that allows arbitrary file read/write
CriticalCVSS 9.6No exploitEPSS 1%charm · wishMay 7, 2026
- CVE-2026-3083236Monitor
Soft Serve: SSRF via unvalidated LFS endpoint in repo import
CriticalCVSS 9.1No exploitEPSS 0%charm · soft serveMar 7, 2026
- CVE-2026-2405832Monitor
Soft Serve has Critical Authentication Bypass
HighCVSS 8.1No exploitEPSS 1%charm · soft serveJan 22, 2026
- CVE-2023-4380930Monitor
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled
HighCVSS 7.5No exploitEPSS 1%charm · soft serveOct 4, 2023
- CVE-2025-6452230Monitor
Soft Serve is vulnerable to SSRF through its Webhooks
HighCVSS 7.6No exploitEPSS 0%charm · soft serveNov 10, 2025
- CVE-2026-3335328Monitor
Soft Serve: Authenticated repo import can clone server-local private repositories
HighCVSS 7.1No exploitEPSS 0%charm · soft serveMar 24, 2026
- CVE-2025-2213021Monitor
Soft Serve allows path traversal attacks
MediumCVSS 5.3No exploitEPSS 1%charm · soft serveJan 8, 2025
- CVE-2026-2225321Monitor
Soft Serve is missing an authorization check in LFS lock deletion
MediumCVSS 5.4No exploitEPSS 0%charm · soft serveJan 8, 2026