Skip to content
Noroxi

spaceapplications records

14 published records for vendor spaceapplications.

All records

14 records
  • Yamcs: No Rate Limiting on Authentication Endpoint

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    spaceapplications · yamcsJul 16, 2026

  • Yamcs: Remote Code Execution via Mission Database algorithm override

    CriticalCVSS 9.8No exploitEPSS 1%

    spaceapplications · yamcsJul 16, 2026

  • Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via craf

    CriticalCVSS 9.1No exploitEPSS 2%

    spaceapplications · yamcsOct 19, 2023

  • Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection

    CriticalCVSS 9.1No exploitEPSS 1%

    spaceapplications · yamcsJul 16, 2026

  • Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`

    CriticalCVSS 9.1No exploitEPSS 1%

    spaceapplications · yamcsJul 16, 2026

  • Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2).

    HighCVSS 7.5Proof of conceptEPSS 1%

    spaceapplications · yamcsOct 19, 2023

  • An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.

    MediumCVSS 6.1No exploitEPSS 0%

    spaceapplications · yacmsNov 20, 2023

  • An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

    MediumCVSS 6.1No exploitEPSS 0%

    spaceapplications · yamcsOct 19, 2023

  • Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via craft

    MediumCVSS 5.4No exploitEPSS 1%

    spaceapplications · yacmsNov 20, 2023

  • Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the t

    MediumCVSS 5.4No exploitEPSS 1%

    spaceapplications · yacmsNov 20, 2023

  • Yamcs 5.8.6 allows XSS (issue 2 of 2).

    MediumCVSS 5.4No exploitEPSS 1%

    spaceapplications · yamcsOct 19, 2023

  • Yamcs 5.8.6 allows XSS (issue 1 of 2).

    MediumCVSS 5.4No exploitEPSS 0%

    spaceapplications · yamcsOct 19, 2023

  • Yamcs: Unauthorized user enumeration via IAM API endpoints

    MediumCVSS 4.3Proof of conceptEPSS 1%

    spaceapplications · yamcsJul 16, 2026

  • Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets

    MediumCVSS 4.3No exploitEPSS 0%

    spaceapplications · yamcsJul 16, 2026