Vulnerabilities > Taoensso

DATE CVE VULNERABILITY TITLE RISK
2020-09-11 CVE-2020-24164 Deserialization of Untrusted Data vulnerability in Taoensso Nippy
A deserialization flaw is present in Taoensso Nippy before 2.14.2.
local
low complexity
taoensso CWE-502
7.8
2019-02-04 CVE-2019-1000022 Cross-Site Request Forgery (CSRF) vulnerability in Taoensso Sente
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token.
network
low complexity
taoensso CWE-352
8.8