Vulnerabilities > Raneto Project

DATE CVE VULNERABILITY TITLE RISK
2022-08-04 CVE-2022-35142 Improper Authentication vulnerability in Raneto Project Raneto
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
network
low complexity
raneto-project CWE-287
7.5
2022-08-04 CVE-2022-35143 Weak Password Requirements vulnerability in Raneto Project Raneto
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
network
low complexity
raneto-project CWE-521
critical
9.8
2022-08-04 CVE-2022-35144 Cross-site Scripting vulnerability in Raneto Project Raneto
Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
network
low complexity
raneto-project CWE-79
4.8