craws records
16 published records for vendor craws.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-1392 Use of Default Credentials1
- CWE-203 Observable Discrepancy1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-51536No exploit | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.craws · openatlas · CWE-798 | Critical9.8 | — | 0.5% | Aug 4, 2025 |
36Monitor | CVE-2025-51535No exploit | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.craws · openatlas · CWE-1392 | Critical9.1 | — | 0.4% | Aug 4, 2025 |
32Monitor | CVE-2025-60915No exploit | An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execcraws · openatlas · CWE-22 | High8.1 | — | 0.4% | Nov 24, 2025 |
32Monitor | CVE-2025-51534No exploit | A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrarycraws · openatlas · CWE-79 | High8.1 | — | 0.4% | Aug 4, 2025 |
21Monitor | CVE-2025-56423No exploit | An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitcraws · openatlas · CWE-203 | Medium5.3 | — | 0.3% | Nov 24, 2025 |
21Monitor | CVE-2025-60916No exploit | A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas beforcraws · openatlas · CWE-79 | Medium5.4 | — | 0.2% | Nov 24, 2025 |
20Monitor | CVE-2025-40708No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40709No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40702No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40703No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40704No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40705No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40706No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
20Monitor | CVE-2025-40707No exploit | Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CHcraws · openatlas · CWE-79 | Medium5.1 | — | 0.2% | Aug 29, 2025 |
18Monitor | CVE-2025-60917No exploit | A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas beforcraws · openatlas · CWE-79 | Medium4.6 | — | 0.2% | Nov 24, 2025 |
18Monitor | CVE-2025-60914No exploit | Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via craws · openatlas · CWE-79 | Medium4.6 | — | 0.2% | Nov 24, 2025 |
- CVE-2025-5153639Monitor
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
CriticalCVSS 9.8No exploitEPSS 1%craws · openatlasAug 4, 2025
- CVE-2025-5153536Monitor
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
CriticalCVSS 9.1No exploitEPSS 0%craws · openatlasAug 4, 2025
- CVE-2025-6091532Monitor
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to exec
HighCVSS 8.1No exploitEPSS 0%craws · openatlasNov 24, 2025
- CVE-2025-5153432Monitor
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary
HighCVSS 8.1No exploitEPSS 0%craws · openatlasAug 4, 2025
- CVE-2025-5642321Monitor
An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensit
MediumCVSS 5.3No exploitEPSS 0%craws · openatlasNov 24, 2025
- CVE-2025-6091621Monitor
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas befor
MediumCVSS 5.4No exploitEPSS 0%craws · openatlasNov 24, 2025
- CVE-2025-4070820Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070920Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070220Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070320Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070420Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070520Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070620Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-4070720Monitor
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
MediumCVSS 5.1No exploitEPSS 0%craws · openatlasAug 29, 2025
- CVE-2025-6091718Monitor
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas befor
MediumCVSS 4.6No exploitEPSS 0%craws · openatlasNov 24, 2025
- CVE-2025-6091418Monitor
Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via
MediumCVSS 4.6No exploitEPSS 0%craws · openatlasNov 24, 2025