WinterChenS records
5 published records for vendor winterchens.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control3
- CWE-287 Improper Authentication1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-53496No exploit | Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentiwinterchens · my-site · CWE-284 | Critical9.8 | — | 0.6% | Aug 22, 2025 |
39Monitor | CVE-2025-50904No exploit | There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11).winterchens · my-site · CWE-288 | Critical9.8 | — | 0.4% | Aug 20, 2025 |
30Monitor | CVE-2024-53495No exploit | Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentwinterchens · my-site · CWE-284 | High7.5 | — | 0.4% | Aug 20, 2025 |
30Monitor | CVE-2024-57152No exploit | Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication winterchens · my-site · CWE-284 | High7.5 | — | 0.4% | Aug 20, 2025 |
22Monitor | CVE-2025-8838No exploit | WinterChenS my-site Backend admin preHandle improper authenticationwinterchens · my-site · CWE-287 | Medium5.5 | — | 0.5% | Aug 11, 2025 |
- CVE-2024-5349639Monitor
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authenti
CriticalCVSS 9.8No exploitEPSS 1%winterchens · my-siteAug 22, 2025
- CVE-2025-5090439Monitor
There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11).
CriticalCVSS 9.8No exploitEPSS 0%winterchens · my-siteAug 20, 2025
- CVE-2024-5349530Monitor
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authent
HighCVSS 7.5No exploitEPSS 0%winterchens · my-siteAug 20, 2025
- CVE-2024-5715230Monitor
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication
HighCVSS 7.5No exploitEPSS 0%winterchens · my-siteAug 20, 2025
- CVE-2025-883822Monitor
WinterChenS my-site Backend admin preHandle improper authentication
MediumCVSS 5.5No exploitEPSS 1%winterchens · my-siteAug 11, 2025