Skip to content
Noroxi

Salesforce records

21 published records for vendor salesforce.

All records

21 records
  • Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cooki

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    salesforce · tough-cookieJul 1, 2023

  • MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both Cloud

    CriticalCVSS 9.8No exploitEPSS 2%

    salesforce · muleMar 26, 2021

  • CVE-2021-1628
    39Monitor

    MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both C

    CriticalCVSS 9.8No exploitEPSS 1%

    salesforce · muleMar 26, 2021

  • CVE-2021-1627
    39Monitor

    MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both

    CriticalCVSS 9.8No exploitEPSS 1%

    salesforce · muleMar 26, 2021

  • Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (C

    CriticalCVSS 9.8No exploitEPSS 1%

    salesforce · marketing cloud engagementJan 23, 2026

  • Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (M

    CriticalCVSS 9.8No exploitEPSS 1%

    salesforce · marketing cloud engagementJan 23, 2026

  • forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    salesforce · mobile software development kitJan 7, 2023

  • Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscr

    CriticalCVSS 9.8No exploitEPSS 1%

    salesforce · marketing cloud engagementJan 23, 2026

  • Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr

    CriticalCVSS 9.8No exploitEPSS 0%

    salesforce · marketing cloud engagementJan 23, 2026

  • Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Execut

    CriticalCVSS 9.8No exploitEPSS 0%

    salesforce · uni2tsJan 9, 2026

  • An issue was discovered in the Docusign API package 8.142.14 for Salesforce.

    HighCVSS 8.1No exploitEPSS 1%

    Aug 21, 2024

  • A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.

    HighCVSS 7.5No exploitEPSS 3%

    salesforce · tough-cookieOct 3, 2017

  • CVE-2021-1630
    30Monitor

    XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime F

    HighCVSS 7.5No exploitEPSS 1%

    salesforce · muleAug 5, 2021

  • Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This is

    MediumCVSS 6.5No exploitEPSS 0%

    salesforce · agentforce vibesNov 4, 2025

  • Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.Thi

    MediumCVSS 6.5No exploitEPSS 0%

    salesforce · mulesoft anypoint code builderNov 4, 2025

  • NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result

    MediumCVSS 5.3No exploitEPSS 2%

    salesforce · tough-cookieSep 5, 2018

  • Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Write

    MediumCVSS 5.3No exploitEPSS 0%

    salesforce · mulesoft anypoint code builderNov 4, 2025

  • Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable

    MediumCVSS 5.3No exploitEPSS 0%

    salesforce · agentforce vibesNov 4, 2025

  • Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable C

    MediumCVSS 5.3No exploitEPSS 0%

    salesforce · agentforce vibesNov 4, 2025

  • Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeab

    MediumCVSS 5.3No exploitEPSS 0%

    salesforce · mulesoft anypoint code builderNov 4, 2025

  • Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessions

    MediumCVSS 5.1No exploitEPSS 0%

    salesforce · workbenchApr 6, 2026