Products: 3
    Vulnerabilities: 9
    Known Exploited: 0
    3
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-47244

    Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information. Exploitation can occur if Anonymous access is enabled, or if there is a successful CSRF attack.

    Last Modified: Apr 15, 2026
    Published: May 03, 2025

    CVE-2017-15608

    Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.

    Last Modified: Nov 21, 2024
    Published: Sep 26, 2018

    CVE-2017-17086

    Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact, as demonstrated by the Plan Editor.

    Last Modified: Apr 20, 2025
    Published: Dec 01, 2017

    CVE-2017-15607

    Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.

    Last Modified: Apr 20, 2025
    Published: Dec 01, 2017

    CVE-2017-16520

    Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.

    Last Modified: Apr 20, 2025
    Published: Nov 11, 2017
    Items Per Page
    Inedo Vulnerabilities & Security CVEs | CVE-DB