CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-4399CRITICAL | CAS <= 1.0.0 - Unauthenticated SSRFThe does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack | CVSS9.1v3.1 | EPSS1.82% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-4388HIGH | CAS <= 1.0.0 - Unauthenticated Arbitrary File AccessThis does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server CWE-22May 23, 2024 | CVSS7.5v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |