Known vulnerabilities in caldera
Software:
caldera
Software CPE:
cpe:2.3:a:the_mitre_corporation_and_mit_kit:caldera:*:*:*:*:*:*:*:*
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU34246 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-14462 |
CWE-79 | Low | 2.8.0 | 19.06.2020 |
SB2020061972 |
||
| #VU26316 - Improper Authentication CVE-2020-10807 |
CWE-287 | High | 2.6.5 | 23.03.2020 |
SB2020032309 |
||
| #VU41712 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2014-2933 |
CWE-22 | Medium | - | 08.05.2014 |
SB2014050806 |
||
| #VU41713 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2014-2934 |
CWE-89 | Medium | - | 08.05.2014 |
SB2014050806 |
||
| #VU41714 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2014-2935 |
CWE-78 | High | - | 08.05.2014 |
SB2014050806 |
||
| #VU41715 - Improper Control of Generation of Code ('Code Injection') CVE-2014-2936 |
CWE-94 | Medium | - | 08.05.2014 |
SB2014050806 |