tolgee kayıtları
tolgee üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-862 Missing Authorization2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-32251İstismar yok | Tolgee has an XXE Injection in Translation Importtolgee · tolgee · CWE-611 | Kritik9,3 | — | %0,4 | 12 Mar 2026 |
32İzleyin | CVE-2023-38510İstismar yok | Tolgee Lacks Permission Check for API Key for some endpointstolgee · tolgee · CWE-862 | Yüksek8,1 | — | %0,6 | 27 Tem 2023 |
30İzleyin | CVE-2024-52297İstismar yok | Tolgee's configuration all configuration properties leaked in public configuration DTOtolgee · tolgee · CWE-200 | Yüksek7,5 | — | %0,6 | 12 Kas 2024 |
26İzleyin | CVE-2024-32470İstismar yok | Tolgee' API keys created by server admin users bypass the permission checktolgee · tolgee · CWE-863 | Orta6,5 | — | %0,6 | 18 Nis 2024 |
21İzleyin | CVE-2023-41316İstismar yok | HTML Injection with email in Tolgeetolgee · tolgee · CWE-20 | Orta5,4 | — | %0,5 | 7 Eyl 2023 |
17İzleyin | CVE-2024-32466İstismar yok | Tolgee's API key scopes not checked when querying translation datatolgee · tolgee · CWE-862 | Orta4,3 | — | %0,4 | 18 Nis 2024 |
- CVE-2026-3225137İzleyin
Tolgee has an XXE Injection in Translation Import
KritikCVSS 9,3İstismar yokEPSS %0tolgee · tolgee12 Mar 2026
- CVE-2023-3851032İzleyin
Tolgee Lacks Permission Check for API Key for some endpoints
YüksekCVSS 8,1İstismar yokEPSS %1tolgee · tolgee27 Tem 2023
- CVE-2024-5229730İzleyin
Tolgee's configuration all configuration properties leaked in public configuration DTO
YüksekCVSS 7,5İstismar yokEPSS %1tolgee · tolgee12 Kas 2024
- CVE-2024-3247026İzleyin
Tolgee' API keys created by server admin users bypass the permission check
OrtaCVSS 6,5İstismar yokEPSS %1tolgee · tolgee18 Nis 2024
- CVE-2023-4131621İzleyin
HTML Injection with email in Tolgee
OrtaCVSS 5,4İstismar yokEPSS %0tolgee · tolgee7 Eyl 2023
- CVE-2024-3246617İzleyin
Tolgee's API key scopes not checked when querying translation data
OrtaCVSS 4,3İstismar yokEPSS %0tolgee · tolgee18 Nis 2024