VulnSea

automate vulnerabilities

CVEs whose affected-version data names the automate package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2025-11493High· 8.8
11mo ago

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle a…

▾ Twilightconnectwise · automateEPSS 0.23%via NVD
CVE-2025-11492Critical· 9.6PoC
11mo ago

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic.…

▾ Abyssalconnectwise · automateEPSS 0.21%via NVD
CVE-2025-8868Critical· 9.8PoC
1y ago

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in a…

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in a…

▾ Abyssalchef · automateEPSS 24%via NVD
CVE-2025-6724High· 8.8
1y ago

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL c…

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL c…

▾ Twilightchef · automateEPSS 0.37%via NVD
automate vulnerabilities (CVEs) · VulnSea