anuko records
12 published records for vendor anuko.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 58.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2020-27422Proof of concept | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the sanuko · time tracker · CWE-613 | Critical9.8 | — | 7.9% | Nov 16, 2020 |
39Monitor | CVE-2023-32306No exploit | Time Tracker has Blind SQL Injection Vulnerability in Reportsanuko · time tracker · CWE-89 | Critical9.8 | — | 0.7% | May 12, 2023 |
39Monitor | CVE-2023-32308No exploit | SQL Injection Vulnerability in anuko timetrackeranuko · time tracker · CWE-89 | Critical9.8 | — | 0.7% | May 15, 2023 |
37Monitor | CVE-2022-24707Proof of concept | SQL injection in anuko timetrackeranuko · time tracker · CWE-89 | High8.8 | — | 7.2% | Feb 24, 2022 |
36Monitor | CVE-2021-21352No exploit | Predictable tokens used for password resetsanuko · time tracker · CWE-330 | Critical9.1 | — | 1.5% | Mar 2, 2021 |
35Monitor | CVE-2021-43851No exploit | SQL injection vulnerability in anuko timetrackeranuko · time tracker · CWE-89 | High8.8 | — | 1.2% | Dec 21, 2021 |
32Monitor | CVE-2020-27423Proof of concept | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on anuko · time tracker · CWE-307 | High7.5 | — | 6.4% | Nov 16, 2020 |
32Monitor | CVE-2021-29436No exploit | Cross site request forgery vulnerabilityanuko · time tracker · CWE-352 | High8.1 | — | 0.5% | Apr 13, 2021 |
30Monitor | CVE-2020-15255Proof of concept | CSV injection in Anuko Time Trackeranuko · time tracker · CWE-74 | High7.3 | — | 3.5% | Oct 16, 2020 |
24Monitor | CVE-2021-41139No exploit | Reflected XSS vulnerability in time.phpanuko · time tracker · CWE-79 | Medium6.1 | — | 1.0% | Oct 13, 2021 |
21Monitor | CVE-2022-24708No exploit | Stored XSS vulnerability in anuko/timetrackeranuko · time tracker · CWE-79 | Medium5.4 | — | 0.6% | Feb 24, 2022 |
21Monitor | CVE-2023-32066No exploit | Time Tracker has Stored XSS vulnerability in Week View pluginanuko · time tracker · CWE-79 | Medium5.4 | — | 0.4% | May 9, 2023 |
- CVE-2020-2742241Plan
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s
CriticalCVSS 9.8Proof of conceptEPSS 8%anuko · time trackerNov 16, 2020
- CVE-2023-3230639Monitor
Time Tracker has Blind SQL Injection Vulnerability in Reports
CriticalCVSS 9.8No exploitEPSS 1%anuko · time trackerMay 12, 2023
- CVE-2023-3230839Monitor
SQL Injection Vulnerability in anuko timetracker
CriticalCVSS 9.8No exploitEPSS 1%anuko · time trackerMay 15, 2023
- CVE-2022-2470737Monitor
SQL injection in anuko timetracker
HighCVSS 8.8Proof of conceptEPSS 7%anuko · time trackerFeb 24, 2022
- CVE-2021-2135236Monitor
Predictable tokens used for password resets
CriticalCVSS 9.1No exploitEPSS 2%anuko · time trackerMar 2, 2021
- CVE-2021-4385135Monitor
SQL injection vulnerability in anuko timetracker
HighCVSS 8.8No exploitEPSS 1%anuko · time trackerDec 21, 2021
- CVE-2020-2742332Monitor
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on
HighCVSS 7.5Proof of conceptEPSS 6%anuko · time trackerNov 16, 2020
- CVE-2021-2943632Monitor
Cross site request forgery vulnerability
HighCVSS 8.1No exploitEPSS 1%anuko · time trackerApr 13, 2021
- CVE-2020-1525530Monitor
CSV injection in Anuko Time Tracker
HighCVSS 7.3Proof of conceptEPSS 4%anuko · time trackerOct 16, 2020
- CVE-2021-4113924Monitor
Reflected XSS vulnerability in time.php
MediumCVSS 6.1No exploitEPSS 1%anuko · time trackerOct 13, 2021
- CVE-2022-2470821Monitor
Stored XSS vulnerability in anuko/timetracker
MediumCVSS 5.4No exploitEPSS 1%anuko · time trackerFeb 24, 2022
- CVE-2023-3206621Monitor
Time Tracker has Stored XSS vulnerability in Week View plugin
MediumCVSS 5.4No exploitEPSS 0%anuko · time trackerMay 9, 2023