Epikur develops a focused authentication and credential-management product that is more prominent in vulnerability disclosures than its narrow vendor footprint might suggest. The durable weakness signal centers on authentication handling—recurrent issues include improper and missing authentication controls for critical functions alongside insufficient password-hashing implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Epikur over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10539CRITICAL An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user passw | Feb 5, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-10537HIGH An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP port 4848. No password is required to access it with the admi | Feb 5, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-10538MEDIUM An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be us | Feb 5, 2021 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Epikur.
Media articles that mention a CVE ID that affects a product developed by Epikur — matched by CVE ID, not by vendor name.