Skip to main content

Vendor/product archive

xorux / lpar2rrd CVEs

Beta · best-effort

9 CVEs tagged to xorux / lpar2rrd4 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-54769

Published Jul 29, 2025

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwri…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-54768

Published Jul 29, 2025

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used t…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-54767

Published Jul 29, 2025

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2021-42372

Published Nov 8, 2021

A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42370

Published Nov 8, 2021

A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device propertie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24032

Published Aug 18, 2020

tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4981

Published Feb 17, 2020

LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4982

Published Jan 10, 2020

LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1