Package Analytics
Sick · 16 CVEs
Username Disclosure Through Missing Authentication
Oct 6, 2025
Path Traversal
Oct 6, 2025
Path traversal
Oct 6, 2025
Information Disclosure Through Stacktrace
Oct 6, 2025
Improper Restriction of Excessive Authentication Attempts
Oct 6, 2025
User Enumeration by excessive error output
Oct 6, 2025
Sensitive Information Disclosure Through Missing Authentication
Oct 6, 2025
Plain Text Transmission of Username and Password in the URL
Oct 6, 2025
The credentials of the users stored in the system's local database can be used for the log in, making it possible for a…
Oct 6, 2025
Cross Site Scripting: Session Hijacking
Oct 6, 2025
Missing HTTP Security Headers
Jun 12, 2025
No brute-force protection
Jun 12, 2025
Information disclosure to unauthorized user
Jun 12, 2025
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.…
Jul 29, 2020
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions…
Jul 29, 2020
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by direc…
Jul 29, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-58579 | Username Disclosure Through Missing Authentication | MEDIUM | 0.40% | Oct 6, 2025 |
| CVE-2025-58591 | Path Traversal | HIGH | 0.53% | Oct 6, 2025 |
| CVE-2025-58590 | Path traversal | HIGH | 0.53% | Oct 6, 2025 |
| CVE-2025-58589 | Information Disclosure Through Stacktrace | MEDIUM | 0.36% | Oct 6, 2025 |
| CVE-2025-58587 | Improper Restriction of Excessive Authentication Attempts | CRITICAL | 0.49% | Oct 6, 2025 |
| CVE-2025-58586 | User Enumeration by excessive error output | MEDIUM | 0.36% | Oct 6, 2025 |
| CVE-2025-58585 | Sensitive Information Disclosure Through Missing Authentication | HIGH | 0.43% | Oct 6, 2025 |
| CVE-2025-58584 | Plain Text Transmission of Username and Password in the URL | HIGH | 0.39% | Oct 6, 2025 |
| CVE-2025-9914 | The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access.… | HIGH | 0.32% | Oct 6, 2025 |
| CVE-2025-9913 | Cross Site Scripting: Session Hijacking | MEDIUM | 0.29% | Oct 6, 2025 |
| CVE-2025-49193 | Missing HTTP Security Headers | MEDIUM | 0.31% | Jun 12, 2025 |
| CVE-2025-49186 | No brute-force protection | MEDIUM | 0.37% | Jun 12, 2025 |
| CVE-2025-49184 | Information disclosure to unauthorized user | HIGH | 0.49% | Jun 12, 2025 |
| CVE-2020-2078 | Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access… | MEDIUM | 0.75% | Jul 29, 2020 |
| CVE-2020-2077 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker coul… | HIGH | 1.01% | Jul 29, 2020 |
| CVE-2020-2076 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An at… | CRITICAL | 1.26% | Jul 29, 2020 |
Showing 1 to 16 of 16 CVEs