İçeriğe atla
Noroxi

dradisframework kayıtları

dradisframework üreticisine ait 6 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%16,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

6 kayıt
  • CVE-2019-19946
    26İzleyin

    The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

    OrtaCVSS 6,5İstismar yokEPSS %1

    dradisframework · dradis16 Mar 2020

  • CVE-2022-30028
    23İzleyin

    Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.

    OrtaCVSS 5,9İstismar yokEPSS %1

    dradisframework · dradis24 Haz 2022

  • CVE-2019-5925
    21İzleyin

    Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3

    OrtaCVSS 5,4İstismar yokEPSS %1

    dradisframework · dradis12 Mar 2019

  • CVE-2023-31223
    21İzleyin

    Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.

    OrtaCVSS 5,4İstismar yokEPSS %1

    dradisframework · dradis25 Nis 2023

  • CVE-2023-50786
    17İzleyin

    Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.

    OrtaCVSS 4,3İstismar yokEPSS %0

    dradisframework · dradis5 Tem 2025

  • CVE-2023-50458
    17İzleyin

    In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

    OrtaCVSS 4,3İstismar yokEPSS %0

    dradisframework · dradis10 Tem 2025