Vulnerabilities in RRWO
18 resultsVexday analysis
O fornecedor RRWO apresenta 16 vulnerabilidades registradas, com 14 delas publicadas nos últimos 90 dias, indicando atividade recente de descoberta ou divulgação. Nenhuma vulnerabilidade está sob ataque ativo (KEV), e apenas 1 é classificada como crítica, sugerindo risco moderado no momento. A fraqueza dominante é CWE-150, o que requer validação técnica específica para impacto real na infraestrutura.
CVE-2026-16766CRITICALCatalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render optionsEPSS 1.3%CVE-2026-7040HIGHText::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have heap overflow when processing some malformed UTF-8 charactersEPSS 0.4%CVE-2026-47372CRITICALCrypt::SaltedHash versions through 0.09 for Perl generate insecure random values for saltsEPSS 0.4%CVE-2026-47373HIGHCrypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacksEPSS 0.4%CVE-2025-3051MEDIUMLinux::Statm::Tiny for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2026-17552CRITICALPlack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in callEPSS 0.3%CVE-2026-46720HIGHNet::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-49941HIGHNet::CIDR::Set versions through 0.20 for Perl did not validate IP addressesEPSS 0.3%CVE-2026-46740MEDIUMMojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injectionsEPSS 0.3%CVE-2025-40911MEDIUMNet::CIDR::Set versions 0.10 through 0.13 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addressesEPSS 0.3%CVE-2026-49942HIGHNet::CIDR::Set versions through 0.20 for Perl did not validate network masksEPSS 0.3%CVE-2026-46719MEDIUMNet::Statsd::Lite versions before 0.9.0 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-45180HIGHCatalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session idsEPSS 0.2%CVE-2026-8788HIGHNet::Statsd::Lite versions through 0.10.0 for Perl allowed metric injectionsEPSS 0.2%CVE-2026-9658HIGHPlack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request pathsEPSS 0.2%CVE-2026-45179MEDIUMPlack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addressesEPSS 0.2%CVE-2026-49940MEDIUMNet::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasksEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%