Vulnerabilities (CVE)

Filtered by vendor Yaws Subscribe
Filtered by product Yaws
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24379 1 Yaws 1 Yaws 2020-10-17 6.8 MEDIUM 9.8 CRITICAL
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
CVE-2020-24916 1 Yaws 1 Yaws 2020-10-17 10.0 HIGH 9.8 CRITICAL
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.