Ikus Soft maintains a focused product portfolio centered on backup and disaster-recovery solutions, with primary exposure identified in rdiffweb and Minarca. Despite a narrow product footprint, the vendor occupies a more prominent position in the vulnerability landscape than its size might suggest, reflecting the critical role backup infrastructure plays in business continuity. Vulnerabilities affecting this vendor have not clustered into a single recurrent weakness class, indicating sporadic rather than structural defect patterns across its disclosures. Defenders should treat backup-infrastructure vendors as part of supply-chain inventory because compromise of backup systems can have outsized consequences for recovery and forensics; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ikus Soft over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4724CRITICAL Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. | Dec 27, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-3363CRITICAL Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. | Oct 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-3269CRITICAL Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. | Sep 23, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-3362CRITICAL Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. | Nov 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3327CRITICAL Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. | Oct 20, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3439CRITICAL Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. | Oct 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3457CRITICAL Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3456CRITICAL Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3268CRITICAL Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. | Sep 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-4314CRITICAL Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. | Dec 12, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ikus Soft.
Media articles that mention a CVE ID that affects a product developed by Ikus Soft — matched by CVE ID, not by vendor name.