CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-67796HIGH | IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other usersIKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. CWE-284May 4, 2026 | CVSS8.1v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4. CWE-770Sep 29, 2023 | CVSS-v4.0 | EPSS0.652% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-4138MEDIUM | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0. CWE-770Aug 3, 2023 | CVSS6.5v3.1 | EPSS0.448% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Authentication Bypass by Primary Weakness in ikus060/rdiffwebAuthentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. | CVSS-v4.0 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Open Redirect in ikus060/rdiffwebOpen Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5. CWE-601Dec 23, 2022 | CVSS-v4.0 | EPSS0.481% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Business Logic Errors in ikus060/rdiffwebBusiness Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. CWE-840Dec 23, 2022 | CVSS-v4.0 | EPSS0.975% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper Access Control in ikus060/rdiffwebImproper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. CWE-284Dec 23, 2022 | CVSS-v4.0 | EPSS0.827% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in ikus060/rdiffwebFailure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5. CWE-75Dec 23, 2022 | CVSS-v4.0 | EPSS0.485% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5. CWE-770Dec 23, 2022 | CVSS-v4.0 | EPSS0.632% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Open Redirect in ikus060/rdiffwebOpen Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4. CWE-601Dec 22, 2022 | CVSS-v4.0 | EPSS0.599% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Cross-Site Request Forgery (CSRF) in ikus060/rdiffwebCross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4. CWE-352Dec 22, 2022 | CVSS-v4.0 | EPSS0.316% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper Privilege Management in ikus060/rdiffwebImproper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. CWE-269Dec 6, 2022 | CVSS-v4.0 | EPSS0.796% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Missing Authentication for Critical Function in ikus060/rdiffwebMissing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. CWE-306Nov 16, 2022 | CVSS-v4.0 | EPSS0.816% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Insufficient Session Expiration in ikus060/rdiffwebInsufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. CWE-613Nov 14, 2022 | CVSS-v4.0 | EPSS0.884% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Business Logic Errors in ikus060/rdiffwebBusiness Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. CWE-840Oct 26, 2022 | CVSS-v4.0 | EPSS0.791% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Missing Authentication for Critical Function in ikus060/rdiffwebMissing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. CWE-306Oct 19, 2022 | CVSS-v4.0 | EPSS0.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-3439CRITICAL | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. CWE-770Oct 14, 2022 | CVSS9.8v3.1 | EPSS0.63% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3457CRITICAL | Origin Validation Error in ikus060/rdiffwebOrigin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5. CWE-346Oct 13, 2022 | CVSS9.8v3.1 | EPSS0.347% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3456CRITICAL | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. CWE-770Oct 13, 2022 | CVSS9.8v3.1 | EPSS0.371% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3438MEDIUM | Open Redirect in ikus060/rdiffwebOpen Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. CWE-601Oct 10, 2022 | CVSS6.1v3.1 | EPSS0.525% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3273CRITICAL | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. | CVSS9.8v3.1 | EPSS0.471% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3376MEDIUM | Weak Password Requirements in ikus060/rdiffwebWeak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. CWE-521Oct 6, 2022 | CVSS5.3v3.1 | EPSS0.724% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Path Traversal in ikus060/rdiffwebPath Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. CWE-22Oct 6, 2022 | CVSS-v4.0 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
No limit in length of "Token name" parameter results in DOS attack /memory corruption in ikus060/rdiffweb prior to 2.5.0a3 in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. CWE-770Sep 30, 2022 | CVSS-v4.0 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
No limit in length of "Fullname" parameter results in DOS attack /memory corruption in ikus060/rdiffweb prior to 2.5.0a3 in ikus060/rdiffwebAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. CWE-770Sep 29, 2022 | CVSS-v4.0 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |