Products: 5
    Vulnerabilities: 17
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    7
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-82477

    SSRF via Tenable Proxy Endpoint in Heimdall 2.11.6-2.13.x

    Last Modified: Sep 01, 2026
    Published: Aug 29, 2026

    CVE-2025-27364

    In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.

    Last Modified: Apr 15, 2026
    Published: Feb 24, 2025

    CVE-2023-51792

    Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.

    Last Modified: Apr 15, 2026
    Published: Apr 19, 2024

    CVE-2022-40605

    MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.

    Last Modified: May 14, 2025
    Published: Oct 17, 2022

    CVE-2022-41139

    MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.

    Last Modified: May 14, 2025
    Published: Oct 17, 2022
    Items Per Page
    Mitre Vulnerabilities & Security CVEs | CVE-DB