Vulnerabilities > Mulesoft > High

DATE CVE VULNERABILITY TITLE RISK
2020-05-29 CVE-2020-6937 Unspecified vulnerability in Mulesoft Mule Runtime
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
network
low complexity
mulesoft
7.5
2019-08-30 CVE-2019-15630 Path Traversal vulnerability in Mulesoft API Gateway and Mule Runtime
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.
network
low complexity
mulesoft CWE-22
7.5