| CVE ID | Publié | Description | Score | Gravité | 
|---|---|---|---|---|
| A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed. | 5.3  | 
                                Moyen  | 
                            ||
| The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | 7.5  | 
                                Haute  |