dradisframework kayıtları
dradisframework üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1230 Exposure of Sensitive Information Through Metadata1
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
26İzleyin | CVE-2019-19946İstismar yok | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.dradisframework · dradis · CWE-639 | Orta6,5 | — | %1,2 | 16 Mar 2020 |
23İzleyin | CVE-2022-30028İstismar yok | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.dradisframework · dradis · CWE-362 | Orta5,9 | — | %0,5 | 24 Haz 2022 |
21İzleyin | CVE-2019-5925İstismar yok | Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3dradisframework · dradis · CWE-79 | Orta5,4 | — | %0,8 | 12 Mar 2019 |
21İzleyin | CVE-2023-31223İstismar yok | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.dradisframework · dradis · CWE-79 | Orta5,4 | — | %0,5 | 25 Nis 2023 |
17İzleyin | CVE-2023-50786İstismar yok | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.dradisframework · dradis · CWE-294 | Orta4,3 | — | %0,3 | 5 Tem 2025 |
17İzleyin | CVE-2023-50458İstismar yok | In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.dradisframework · dradis · CWE-1230 | Orta4,3 | — | %0,2 | 10 Tem 2025 |
- CVE-2019-1994626İzleyin
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
OrtaCVSS 6,5İstismar yokEPSS %1dradisframework · dradis16 Mar 2020
- CVE-2022-3002823İzleyin
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
OrtaCVSS 5,9İstismar yokEPSS %1dradisframework · dradis24 Haz 2022
- CVE-2019-592521İzleyin
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3
OrtaCVSS 5,4İstismar yokEPSS %1dradisframework · dradis12 Mar 2019
- CVE-2023-3122321İzleyin
Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
OrtaCVSS 5,4İstismar yokEPSS %1dradisframework · dradis25 Nis 2023
- CVE-2023-5078617İzleyin
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.
OrtaCVSS 4,3İstismar yokEPSS %0dradisframework · dradis5 Tem 2025
- CVE-2023-5045817İzleyin
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
OrtaCVSS 4,3İstismar yokEPSS %0dradisframework · dradis10 Tem 2025