CVE-2018-16497High· 7.8▾ TwilightIn Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, the job runs a script as root that is writable by users who are members of the versa group.
versa_analytics < 16.1R2S11versa_analytics >= 20.2.0, < 20.2.2versa_analytics >= 21.1.0, < 21.1.1versa_analytics >= 21.2.0, < 21.2.1Upgrade past the affected range:
versa_analytics 21.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2025-24291Medium· 6.1The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files
CVE-2025-23173High· 7.5The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI
CVE-2025-24288Critical· 9.8The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials
CVE-2019-25029Critical· 9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application
CVE-2026-12470High· 7.2The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' A…