Search
Total
5 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-1432 | 1 Octoprint | 1 Octoprint | 2022-05-25 | 4.6 MEDIUM | 6.4 MEDIUM |
| Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0. | |||||
| CVE-2022-1430 | 1 Octoprint | 1 Octoprint | 2022-05-25 | 5.1 MEDIUM | 7.5 HIGH |
| Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. | |||||
| CVE-2021-32561 | 1 Octoprint | 1 Octoprint | 2021-05-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters. | |||||
| CVE-2021-32560 | 1 Octoprint | 1 Octoprint | 2021-05-26 | 4.0 MEDIUM | 6.5 MEDIUM |
| The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files. | |||||
| CVE-2018-16710 | 1 Octoprint | 1 Octoprint | 2018-11-14 | 6.4 MEDIUM | 9.1 CRITICAL |
| ** DISPUTED ** OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting OctoPrint onto the public internet is a terrible idea, and I really can't emphasize that enough." | |||||
