Skip to content
Noroxi

contribsys records

7 published records for vendor contribsys.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

7 records
  • CVE-2023-1892
    39Monitor

    Cross-site Scripting (XSS) - Reflected in sidekiq/sidekiq

    CriticalCVSS 9.6Proof of conceptEPSS 3%

    contribsys · sidekiqApr 21, 2023

  • In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph.

    HighCVSS 7.5No exploitEPSS 5%

    contribsys · sidekiqJan 21, 2022

  • Faktory Web Dashboard can lead to denial of service(DOS) via malicious user input

    HighCVSS 7.5No exploitEPSS 1%

    contribsys · faktorySep 20, 2023

  • Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

    MediumCVSS 6.1Proof of conceptEPSS 4%

    contribsys · sidekiqApr 6, 2021

  • Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL

    MediumCVSS 6.1No exploitEPSS 1%

    contribsys · sidekiqMar 1, 2024

  • Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payl

    MediumCVSS 6.1No exploitEPSS 1%

    contribsys · sidekiqMar 1, 2024

  • Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js

    MediumCVSS 4.9No exploitEPSS 1%

    contribsys · sidekiqSep 14, 2023