Iscute maintains a lightweight HTTP file-serving application whose vulnerability profile centers on web-layer input-handling defects, particularly cross-site scripting and authentication-bypass weaknesses arising from alternate access paths. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iscute over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-26566HIGH An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component. | Mar 7, 2024 | 8.2 | 24 | NO | NO |
CVE-2023-4118MEDIUM A vulnerability, which was classified as problematic, was found in Cute Http File Server 2.0. This affects an unknown part of the component Search. The manipulation leads to cross | Aug 3, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-50639MEDIUM Cross Site Scripting (XSS) vulnerability in CuteHttpFileServer v.1.0 and v.2.0 allows attackers to obtain sensitive information via the file upload function in the home page. | Dec 20, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iscute.
Media articles that mention a CVE ID that affects a product developed by Iscute — matched by CVE ID, not by vendor name.