passwork records
7 published records for vendor passwork.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-25267No exploit | Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).passwork · passwork · CWE-22 | High8.8 | — | 1.5% | Mar 23, 2022 |
35Monitor | CVE-2022-25268No exploit | Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.passwork · passwork · CWE-352 | High8.8 | — | 0.4% | Mar 23, 2022 |
32Monitor | CVE-2023-49949No exploit | Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.passwork · passwork · CWE-863 | High8.1 | — | 0.6% | Dec 26, 2023 |
30Monitor | CVE-2022-42956No exploit | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.passwork · passwork · CWE-312 | High7.5 | — | 0.4% | Nov 7, 2022 |
30Monitor | CVE-2022-42955No exploit | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.passwork · passwork · CWE-312 | High7.5 | — | 0.4% | Nov 7, 2022 |
24Monitor | CVE-2022-25269No exploit | Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.passwork · passwork · CWE-79 | Medium6.1 | — | 0.6% | Mar 23, 2022 |
17Monitor | CVE-2022-25266No exploit | Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).passwork · passwork · CWE-22 | Medium4.3 | — | 1.0% | Mar 23, 2022 |
- CVE-2022-2526735Monitor
Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).
HighCVSS 8.8No exploitEPSS 2%passwork · passworkMar 23, 2022
- CVE-2022-2526835Monitor
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
HighCVSS 8.8No exploitEPSS 0%passwork · passworkMar 23, 2022
- CVE-2023-4994932Monitor
Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.
HighCVSS 8.1No exploitEPSS 1%passwork · passworkDec 26, 2023
- CVE-2022-4295630Monitor
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
HighCVSS 7.5No exploitEPSS 0%passwork · passworkNov 7, 2022
- CVE-2022-4295530Monitor
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
HighCVSS 7.5No exploitEPSS 0%passwork · passworkNov 7, 2022
- CVE-2022-2526924Monitor
Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.
MediumCVSS 6.1No exploitEPSS 1%passwork · passworkMar 23, 2022
- CVE-2022-2526617Monitor
Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).
MediumCVSS 4.3No exploitEPSS 1%passwork · passworkMar 23, 2022