lynxtechnology CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

lynxtechnology vulnerability overview

Aggregates CVE and security vulnerability intelligence across all lynxtechnology-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-13316 Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server. [email protected] 8.2 2.65% 2025-11-19 2025-11-25
CVE-2025-13315 Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password. [email protected] 9.3 31.94% 2025-11-19 2025-12-02
CVE-2018-9182 Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. [email protected] 6.1 1.38% 2018-06-08 2024-11-21
CVE-2018-9177 Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen. [email protected] 6.1 0.68% 2018-06-08 2024-11-21
CVE-2018-7203 Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all. [email protected] 6.1 2.42% 2018-03-30 2024-11-21
CVE-2018-7171 Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all. [email protected] 7.5 28.24% 2018-03-30 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence