odude records
5 published records for vendor odude.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-288 Authentication Bypass Using an Alternate Path or Channel2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2022-4060Proof of concept | User Post Gallery <= 2.19 - Unauthenticated RCEodude · user post gallery · CWE-94 | Critical9.8 | — | 42.7% | Jan 16, 2023 |
41Plan | CVE-2024-9989Proof of concept | Crypto <= 2.18 - Authentication Bypass via log_inodude · crypto tool · CWE-288 | Critical9.8 | — | 7.1% | Oct 29, 2024 |
39Monitor | CVE-2024-9988No exploit | Crypto <= 2.19 - Authentication Bypass via registerodude · crypto tool · CWE-288 | Critical9.8 | — | 1.1% | Oct 29, 2024 |
35Monitor | CVE-2024-9990No exploit | Crypto <= 2.15 - Cross-Site Request Forgery to Authentication Bypassodude · crypto tool · CWE-352 | High8.8 | — | 0.3% | Oct 29, 2024 |
24Monitor | CVE-2022-0449No exploit | Flexi - Guest Submit < 4.20 - Reflected Cross-Site Scriptingodude · flexi · CWE-79 | Medium6.1 | — | 0.8% | Mar 14, 2022 |
- CVE-2022-406052Plan
User Post Gallery <= 2.19 - Unauthenticated RCE
CriticalCVSS 9.8Proof of conceptEPSS 43%odude · user post galleryJan 16, 2023
- CVE-2024-998941Plan
Crypto <= 2.18 - Authentication Bypass via log_in
CriticalCVSS 9.8Proof of conceptEPSS 7%odude · crypto toolOct 29, 2024
- CVE-2024-998839Monitor
Crypto <= 2.19 - Authentication Bypass via register
CriticalCVSS 9.8No exploitEPSS 1%odude · crypto toolOct 29, 2024
- CVE-2024-999035Monitor
Crypto <= 2.15 - Cross-Site Request Forgery to Authentication Bypass
HighCVSS 8.8No exploitEPSS 0%odude · crypto toolOct 29, 2024
- CVE-2022-044924Monitor
Flexi - Guest Submit < 4.20 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%odude · flexiMar 14, 2022