Vantage6
This hub aggregates every CVE we track for Vantage6, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM8LOW4HIGH4CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Vantage6.
- CVE-2025-43866Vantage6 Server JWT secret not cryptographically secure7.5
- CVE-2025-43863vantage6 lacks brute-force protection on change password functionality9.8
- CVE-2024-32969vantage6 collaboration admins can extend their influence by expanding the collaboration2.7
- CVE-2024-23823CORS settings overly permissive in vantage64.2
- CVE-2024-24770Username timing attack on recover password/MFA token in vantage65.3
- CVE-2024-22193vantage6 unencrypted task can be created in encrypted collaboration3.5
- CVE-2024-21671vantage6 username timing attack3.7
- CVE-2024-21653vantage6 insecure SSH configuration for node and server containers6.5
- CVE-2024-21649Remote code execution 8.8
- CVE-2023-47631vantage6 Node accepts non-whitelisted algorithms from malicious server7.2
- CVE-2023-41882vantage6 Improper Access Control vulnerability5.4
- CVE-2023-41881Deleting a collaboration should also delete linked resources3.7
- CVE-2023-28635Defining resource name as integer in vantage6 may give unintended access5.4
- CVE-2023-23930vantage6's Pickle serialization is insecure5.5
- CVE-2023-23929Refresh tokens do not expire in Vantage68.8
Product normalization is registry-driven with AI assist and human review. How it works