CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2025-59793 CRITICAL

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. H…

CVSS 9.4 EPSS 1.07% Feb 17, 2026
CVE-2025-32355 HIGH

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows spec…

CVSS 7.9 EPSS 1.25% Feb 17, 2026
CVE-2025-27225 HIGH

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint disclo…

CVSS 7.5 EPSS 18.38% Oct 27, 2025
CVE-2025-27224 CRITICAL

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the inp…

CVSS 9.8 EPSS 0.87% Oct 27, 2025
CVE-2025-27223 HIGH

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList.…

CVSS 7.5 EPSS 2.20% Oct 27, 2025
CVE-2025-27222 HIGH

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitiz…

CVSS 8.6 EPSS 2.00% Oct 27, 2025
CVE-2010-20007 HIGH

Seagull FTP v3.3 Build 409 Stack Buffer Overflow

CVSS 8.5 EPSS 0.51% Aug 21, 2025
CVE-2024-45955 HIGH

Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.

CVSS 7.3 EPSS 0.40% Jul 30, 2025
CVE-2023-28509 HIGH

Weak encryption in UniRPC protocol

CVSS 7.5 EPSS 0.28% Mar 29, 2023
CVE-2023-28508 HIGH

Heap corruption in UniRPC service

CVSS 8.8 EPSS 0.90% Mar 29, 2023
CVE-2023-28507 CRITICAL

Memory exhaustion in LZ4 decompression in UniRPC daemon

CVSS 9.8 EPSS 0.92% Mar 29, 2023
CVE-2023-28506 HIGH

Stack buffer overflow in UniRPC service

CVSS 8.8 EPSS 0.91% Mar 29, 2023
CVE-2023-28505 HIGH

Buffer overflow in UniRPC library function

CVSS 8.8 EPSS 0.84% Mar 29, 2023
CVE-2023-28504 CRITICAL

Stack buffer overflow in UniRPC library function

CVSS 9.8 EPSS 1.42% Mar 29, 2023
CVE-2023-28503 CRITICAL

Authentication bypass in UniRPC's udadmin service

CVSS 9.8 EPSS 62.14% Mar 29, 2023
CVE-2023-28502 CRITICAL

Stack buffer overflow in UniRPC's udadmin_server service

CVSS 9.8 EPSS 61.10% Mar 29, 2023
CVE-2023-28501 CRITICAL

Heap buffer overflow in unirpcd

CVSS 9.8 EPSS 1.42% Mar 29, 2023
CVE-2022-25027 HIGH

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by valida…

CVSS 7.5 EPSS 1.06% Jan 12, 2023
CVE-2022-25026 HIGH

A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network…

CVSS 7.5 EPSS 24.35% Jan 12, 2023
CVE-2022-36431 CRITICAL

An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted J…

CVSS 9.8 EPSS 1.19% Dec 1, 2022
CVE-2021-45026 MEDIUM

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

CVSS 6.1 EPSS 1.18% Jun 17, 2022
CVE-2021-45025 HIGH

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Informati…

CVSS 7.5 EPSS 0.58% Jun 17, 2022
CVE-2021-45024 CRITICAL

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

CVSS 9.8 EPSS 1.08% Jun 17, 2022
CVE-2021-29935 HIGH

An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics.

CVSS 7.3 EPSS 1.03% Apr 1, 2021
CVE-2020-35882 HIGH

An issue was discovered in the rocket crate before 0.4.5 for Rust. LocalRequest::clone creates more than one mutable references to the same object, possibly ca…

CVSS 8.1 EPSS 0.97% Dec 31, 2020

Showing 1 to 25 CVEs · page 1 (more available)