Vulnerabilities > EVE NG

DATE CVE VULNERABILITY TITLE RISK
2022-10-20 CVE-2022-31366 Unrestricted Upload of File with Dangerous Type vulnerability in Eve-Ng 2.0.3112
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
network
low complexity
eve-ng CWE-434
7.2
2022-05-04 CVE-2022-27903 OS Command Injection vulnerability in Eve-Ng 2.0.3112/4.0.165
An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.
network
low complexity
eve-ng CWE-78
8.8