Skip to main content

Vendor/product archive

easyvirt / co2scope CVEs

Beta · best-effort

6 CVEs tagged to easyvirt / co2scope3 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-57587

Published Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) use…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-55062

Published Jan 31, 2025

Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53357

Published Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53356

Published Jan 31, 2025

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for genera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53355

Published Jan 31, 2025

Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user vi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53354

Published Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1