Vulnerabilities > Ikus Soft

DATE CVE VULNERABILITY TITLE RISK
2022-09-26 CVE-2022-3301 Improper Cleanup on Thrown Exception vulnerability in Ikus-Soft Rdiffweb
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
network
low complexity
ikus-soft CWE-460
2.4
2022-09-23 CVE-2022-3269 Session Fixation vulnerability in Ikus-Soft Rdiffweb
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
network
low complexity
ikus-soft CWE-384
critical
9.8
2022-09-22 CVE-2022-3274 Cross-Site Request Forgery (CSRF) vulnerability in Ikus-Soft Rdiffweb
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.
network
low complexity
ikus-soft CWE-352
3.5
2022-09-22 CVE-2022-3267 Cross-Site Request Forgery (CSRF) vulnerability in Ikus-Soft Rdiffweb
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
network
low complexity
ikus-soft CWE-352
4.3
2022-09-22 CVE-2022-3268 Weak Password Requirements vulnerability in Ikus-Soft Minarca
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
network
low complexity
ikus-soft CWE-521
critical
9.8
2022-09-21 CVE-2022-3233 Cross-Site Request Forgery (CSRF) vulnerability in Ikus-Soft Rdiffweb
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
network
low complexity
ikus-soft CWE-352
4.3
2022-09-21 CVE-2022-3250 Missing Encryption of Sensitive Data vulnerability in Ikus-Soft Rdiffweb
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
network
low complexity
ikus-soft CWE-311
5.3
2022-09-21 CVE-2022-3251 Missing Encryption of Sensitive Data vulnerability in Ikus-Soft Minarca
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
network
low complexity
ikus-soft CWE-311
5.3
2022-09-17 CVE-2022-3232 Cross-Site Request Forgery (CSRF) vulnerability in Ikus-Soft Rdiffweb
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.
network
low complexity
ikus-soft CWE-352
4.3
2022-09-15 CVE-2022-3221 Cross-Site Request Forgery (CSRF) vulnerability in Ikus-Soft Rdiffweb
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.
network
low complexity
ikus-soft CWE-352
8.8