Skip to content
Noroxi

Keyfactor records

11 published records for vendor keyfactor.

All records

11 records
  • Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of

    CriticalCVSS 9.8No exploitEPSS 0%

    Aug 20, 2024

  • In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an a

    HighCVSS 8.2No exploitEPSS 0%

    keyfactor · ejbcaAug 2, 2023

  • Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

    HighCVSS 7.5No exploitEPSS 0%

    keyfactor · aws orchestratorAug 20, 2024

  • Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.

    HighCVSS 7.5No exploitEPSS 0%

    keyfactor · commandAug 20, 2024

  • A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2.

    MediumCVSS 6.5No exploitEPSS 0%

    keyfactor · signserverNov 13, 2025

  • A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2.

    MediumCVSS 5.4No exploitEPSS 0%

    keyfactor · primekey ejbcaNov 17, 2022

  • Keyfactor EJBCA before 7.10.0 allows XSS.

    MediumCVSS 5.4No exploitEPSS 0%

    keyfactor · kefactor ejbcaNov 17, 2022

  • A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which

    MediumCVSS 5.3No exploitEPSS 0%

    keyfactor · signserverNov 13, 2025

  • An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2.

    MediumCVSS 5.3No exploitEPSS 0%

    keyfactor · signserverNov 13, 2025

  • An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.

    MediumCVSS 4.7No exploitEPSS 0%

    keyfactor · signserverDec 22, 2025

  • The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RF

    LowCVSS 3.1No exploitEPSS 0%

    keyfactor · ejbcaSep 12, 2024