openlibraryfoundation records
3 published records for vendor openlibraryfoundation.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2024-25738No exploit | A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before CWE-918 | Critical9.1 | — | 0.7% | May 22, 2024 |
36Monitor | CVE-2024-23687No exploit | FOLIO mod-data-export-spring Hard-Coded Credentialsopenlibraryfoundation · mod-data-export-spring · CWE-798 | Critical9.1 | — | 0.7% | Jan 19, 2024 |
21Monitor | CVE-2024-23685No exploit | FOLIO mod-remote-storage Hard Coded Credentialsopenlibraryfoundation · mod-remote-storage · CWE-798 | Medium5.3 | — | 0.5% | Jan 19, 2024 |
- CVE-2024-2573836Monitor
A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before
CriticalCVSS 9.1No exploitEPSS 1%May 22, 2024
- CVE-2024-2368736Monitor
FOLIO mod-data-export-spring Hard-Coded Credentials
CriticalCVSS 9.1No exploitEPSS 1%openlibraryfoundation · mod-data-export-springJan 19, 2024
- CVE-2024-2368521Monitor
FOLIO mod-remote-storage Hard Coded Credentials
MediumCVSS 5.3No exploitEPSS 1%openlibraryfoundation · mod-remote-storageJan 19, 2024