Vulnerabilities > Greenbone

DATE CVE VULNERABILITY TITLE RISK
2021-06-21 CVE-2018-25016 Injection vulnerability in Greenbone OS and Greenbone Security Assistant
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
network
low complexity
greenbone CWE-74
critical
9.8
2021-06-21 CVE-2019-25047 Cross-site Scripting vulnerability in Greenbone Security Assistant
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
network
low complexity
greenbone CWE-79
6.1
2016-01-26 CVE-2016-1926 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.
network
low complexity
greenbone fedoraproject CWE-79
6.1