leostream records
5 published records for vendor leostream.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-26574No exploit | Leostream Connection Broker 8.2.x is affected by stored XSS.leostream · connection broker · CWE-79 | Critical9.6 | — | 2.1% | Oct 6, 2020 |
30Monitor | CVE-2018-18817No exploit | The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify regileostream · agent | High7.5 | — | 1.1% | Oct 29, 2018 |
28Monitor | CVE-2021-41550No exploit | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.leostream · connection broker · CWE-434 | High7.2 | — | 1.0% | Jan 18, 2022 |
24Monitor | CVE-2021-38157No exploit | LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter.leostream · connection broker · CWE-79 | Medium6.1 | — | 1.1% | Aug 6, 2021 |
19Monitor | CVE-2021-41551No exploit | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a sleostream · connection broker · CWE-59 | Medium4.9 | — | 1.3% | Jan 18, 2022 |
- CVE-2020-2657439Monitor
Leostream Connection Broker 8.2.x is affected by stored XSS.
CriticalCVSS 9.6No exploitEPSS 2%leostream · connection brokerOct 6, 2020
- CVE-2018-1881730Monitor
The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify regi
HighCVSS 7.5No exploitEPSS 1%leostream · agentOct 29, 2018
- CVE-2021-4155028Monitor
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
HighCVSS 7.2No exploitEPSS 1%leostream · connection brokerJan 18, 2022
- CVE-2021-3815724Monitor
LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter.
MediumCVSS 6.1No exploitEPSS 1%leostream · connection brokerAug 6, 2021
- CVE-2021-4155119Monitor
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a s
MediumCVSS 4.9No exploitEPSS 1%leostream · connection brokerJan 18, 2022