loftware CVE Vulnerabilities & CVE List (8)

Products (CPE): — CVEs: 8

loftware vulnerability overview

Aggregates CVE and security vulnerability intelligence across all loftware-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk xxe and vendor risk path handling and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 18 of 8 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-37234 Loftware Spectrum through 4.6 has unprotected JMX Registry. [email protected] 9.8 0.33% 2024-09-10 2024-09-18
CVE-2023-37233 Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. [email protected] 8.8 0.43% 2024-09-10 2024-09-18
CVE-2023-37232 Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor. [email protected] 7.5 0.36% 2024-09-10 2024-09-18
CVE-2023-37231 Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password. [email protected] 9.8 0.21% 2024-09-10 2025-05-29
CVE-2023-37230 Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. [email protected] 8.8 0.20% 2024-09-10 2025-07-10
CVE-2023-37229 Loftware Spectrum before 5.1 allows SSRF. [email protected] 8.8 0.27% 2024-09-10 2025-07-03
CVE-2023-37227 Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. [email protected] 9.8 0.26% 2024-09-10 2025-05-29
CVE-2023-37226 Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. [email protected] 9.8 0.23% 2024-09-10 2025-05-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence