Vulnerabilities > Litespeedtech > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-20 CVE-2024-44000 Insufficiently Protected Credentials vulnerability in Litespeedtech Litespeed Cache
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1.
network
low complexity
litespeedtech CWE-522
critical
9.8
2024-02-09 CVE-2024-25678 Unspecified vulnerability in Litespeedtech Lsquic
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
network
low complexity
litespeedtech
critical
9.8
2022-05-11 CVE-2022-30592 NULL Pointer Dereference vulnerability in Litespeedtech Lsquic
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
network
low complexity
litespeedtech CWE-476
critical
9.8
2020-01-06 CVE-2020-5519 Improper Input Validation vulnerability in Litespeedtech Openlitespeed
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
network
low complexity
litespeedtech CWE-20
critical
9.8