the-emmons/CVE-Disclosures

the-emmons/CVE-Disclosures

Releases0
A repository of details about CVE-assigned vulnerabilities reported by Ryan Emmons.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

6.1 MEDIUM4.3 MEDIUM

The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.