loadbalancer records
3 published records for vendor loadbalancer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-18864No exploit | Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.loadbalancer · enterprise va max · CWE-79 | Critical9.6 | — | 2.6% | Nov 20, 2018 |
36Monitor | CVE-2020-13378No exploit | Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to exloadbalancer · enterprise va max · CWE-78 | High8.8 | — | 3.3% | May 11, 2023 |
32Monitor | CVE-2020-13377No exploit | The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attackerloadbalancer · enterprise va max · CWE-22 | High8.1 | — | 1.5% | May 12, 2023 |
- CVE-2018-1886439Monitor
Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
CriticalCVSS 9.6No exploitEPSS 3%loadbalancer · enterprise va maxNov 20, 2018
- CVE-2020-1337836Monitor
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to ex
HighCVSS 8.8No exploitEPSS 3%loadbalancer · enterprise va maxMay 11, 2023
- CVE-2020-1337732Monitor
The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker
HighCVSS 8.1No exploitEPSS 2%loadbalancer · enterprise va maxMay 12, 2023