partkeepr records
4 published records for vendor partkeepr.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2022-22701No exploit | PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowinpartkeepr · partkeepr · CWE-200 | Medium6.5 | — | 1.0% | Jan 10, 2022 |
21Monitor | CVE-2021-39390No exploit | Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.partkeepr · partkeepr · CWE-79 | Medium5.4 | — | 0.7% | May 3, 2022 |
19Monitor | CVE-2022-30899No exploit | A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.partkeepr · partkeepr · CWE-79 | Medium4.8 | — | 0.5% | Jun 8, 2022 |
17Monitor | CVE-2022-22702No exploit | PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requestspartkeepr · partkeepr · CWE-918 | Medium4.3 | — | 0.7% | Jan 10, 2022 |
- CVE-2022-2270126Monitor
PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowin
MediumCVSS 6.5No exploitEPSS 1%partkeepr · partkeeprJan 10, 2022
- CVE-2021-3939021Monitor
Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.
MediumCVSS 5.4No exploitEPSS 1%partkeepr · partkeeprMay 3, 2022
- CVE-2022-3089919Monitor
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
MediumCVSS 4.8No exploitEPSS 0%partkeepr · partkeeprJun 8, 2022
- CVE-2022-2270217Monitor
PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests
MediumCVSS 4.3No exploitEPSS 1%partkeepr · partkeeprJan 10, 2022