Home/Product/sick field analytics
Product

sick field analytics

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-49200
all versions
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and
6.5MEDIUM
CVE-2025-49199
all versions
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify a
8.8HIGH
CVE-2025-49196
all versions
A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify
6.5MEDIUM
CVE-2025-49193
all versions
The application fails to implement several security headers. These headers help increase the overall security level of the web app
4.2MEDIUM
CVE-2025-49192
all versions
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to tr
4.3MEDIUM
CVE-2025-49191
all versions
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame
4.8MEDIUM
CVE-2025-49190
all versions
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to o
4.3MEDIUM
CVE-2025-49188
all versions
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
5.3MEDIUM
CVE-2025-49187
all versions
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorr
5.3MEDIUM
CVE-2025-49186
all versions
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, m
5.3MEDIUM
CVE-2025-49185
all versions
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject ma
5.5MEDIUM
CVE-2025-49184
all versions
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin