Loadbalancer's vulnerability footprint is concentrated in its Enterprise VA Max appliance, a web-facing load-balancing and application-delivery platform, with the durable signal centered on input-handling and access-control weaknesses including path traversal, cross-site scripting, and OS command injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Loadbalancer over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13378HIGH Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code. | May 12, 2023 | 8.8 | 29 | NO | NO |
CVE-2018-18864CRITICAL Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed. | Nov 20, 2018 | 9.6 | 29 | NO | NO |
CVE-2020-13377HIGH The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks | May 12, 2023 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Loadbalancer.
Media articles that mention a CVE ID that affects a product developed by Loadbalancer — matched by CVE ID, not by vendor name.