Skip to content
Noroxi

MuleSoft records

6 published records for vendor mulesoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
33.3%
Median publish → KEV
No record has entered KEV

All records

6 records
  • The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializat

    CriticalCVSS 9.8No exploitEPSS 5%

    mulesoft · mule runtimeOct 16, 2019

  • Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers

    CriticalCVSS 9.8No exploitEPSS 2%

    mulesoft · api gatewayDec 1, 2019

  • Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

    CriticalCVSS 9.8No exploitEPSS 1%

    mulesoft · aplkitMar 26, 2020

  • Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augu

    HighCVSS 7.5No exploitEPSS 3%

    mulesoft · api gatewayAug 30, 2019

  • CVE-2020-6937
    30Monitor

    A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers t

    HighCVSS 7.5No exploitEPSS 1%

    mulesoft · mule runtimeMay 29, 2020

  • CVE-2014-9000
    29Monitor

    Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated

    MediumCVSS 6.5Proof of conceptEPSS 9%

    mulesoft · mule enterprise management consoleNov 20, 2014