Vulnerabilities > Canto > Canto > 3.0.7

DATE CVE VULNERABILITY TITLE RISK
2024-04-03 CVE-2024-25096 Unspecified vulnerability in Canto
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc.
network
low complexity
canto
critical
9.8
2022-09-09 CVE-2022-40305 Server-Side Request Forgery (SSRF) vulnerability in Canto
A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.
network
low complexity
canto CWE-918
critical
9.8