VendorsCisathoriumall versions
Vulnerabilities

Cisa Cybersecurity and Infrastructure Security Agency (CISA) Thorium

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-35434
CISA Thorium does not validate TLS connections to Elasticsearch
Published 2025-09-17 · Analyzed
9.8EPSS 0.002
CVE-2025-35433
CISA Thorium does not properly invalidate previously used tokens
Published 2025-09-17 · Analyzed
8.8EPSS 0.003
CVE-2025-35432
CISA Thorium does not rate limit account verification email messages
Published 2025-09-17 · Analyzed
7.5EPSS 0.006
CVE-2025-35436
CISA Thorium account verification email error handling
Published 2025-09-17 · Analyzed
7.5EPSS 0.006
CVE-2025-35430
CISA Thorium insecure downloaded file path validation
Published 2025-09-17 · Analyzed
6.5EPSS 0.005
CVE-2025-35431
CISA Thorium LDAP injection
Published 2025-09-17 · Analyzed
5.4EPSS 0.003
CVE-2025-35435
CISA Thorium download stream divide by zero
Published 2025-09-17 · Analyzed
5.3EPSS 0.004