Skip to main content

Vendor/product archive

oxidized_web_project / oxidized_web CVEs

Beta · best-effort

2 CVEs tagged to oxidized_web_project / oxidized_web1 Critical, 0 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2025-27590

Published Mar 3, 2025

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2019-25088

Published Dec 27, 2022

A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The man…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1