lanol records
4 published records for vendor lanol.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-24 Path Traversal: '../filedir'1
- CWE-305 Authentication Bypass by Primary Weakness1
- CWE-591 Sensitive Data Storage in Improperly Locked Memory1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2025-51661No exploit | A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use localanol · filecodebox · CWE-24 | High7.5 | — | 0.5% | Nov 19, 2025 |
30Monitor | CVE-2025-51663No exploit | A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protectiolanol · filecodebox · CWE-305 | High7.5 | — | 0.4% | Nov 19, 2025 |
21Monitor | CVE-2025-51662No exploit | A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier.lanol · filecodebox · CWE-79 | Medium5.4 | — | 0.2% | Nov 19, 2025 |
21Monitor | CVE-2024-34525No exploit | FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.lanol · filecodebox · CWE-591 | Medium5.3 | — | 0.2% | May 5, 2024 |
- CVE-2025-5166130Monitor
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use loca
HighCVSS 7.5No exploitEPSS 1%lanol · filecodeboxNov 19, 2025
- CVE-2025-5166330Monitor
A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protectio
HighCVSS 7.5No exploitEPSS 0%lanol · filecodeboxNov 19, 2025
- CVE-2025-5166221Monitor
A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier.
MediumCVSS 5.4No exploitEPSS 0%lanol · filecodeboxNov 19, 2025
- CVE-2024-3452521Monitor
FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.
MediumCVSS 5.3No exploitEPSS 0%lanol · filecodeboxMay 5, 2024