Skip to content
Noroxi

Sentry records

21 published records for vendor sentry.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
81%
Median publish → KEV
No record has entered KEV

All records

21 records
  • Sentry: Improper authentication on SAML SSO process allows user identity linking

    CriticalCVSS 9.8No exploitEPSS 1%

    sentry · sentryMay 8, 2026

  • Sentry: Improper Authentication on SAML SSO process allows user identity linking

    CriticalCVSS 9.1No exploitEPSS 1%

    sentry · sentryFeb 21, 2026

  • Sentry 8.2.0 Remote Code Execution via Pickle Deserialization

    HighCVSS 8.7No exploitEPSS 1%

    sentry · sentryMay 10, 2026

  • Sentry vulnerable to privilege escalation via ApiTokensEndpoint

    HighCVSS 8.1No exploitEPSS 1%

    sentry · sentryAug 7, 2023

  • Sentry's Astro SDK vulnerable to ReDoS

    HighCVSS 7.5No exploitEPSS 1%

    sentry · astroDec 20, 2023

  • Sentry: Inefficient Regular Expression Complexity in sentry

    HighCVSS 7.5No exploitEPSS 0%

    sentry · sentryJun 24, 2026

  • Sentry vulnerable to incorrect credential validation on OAuth token requests

    MediumCVSS 6.8No exploitEPSS 0%

    sentry · sentryAug 9, 2023

  • Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`

    MediumCVSS 6.5No exploitEPSS 1%

    sentry · sentry software development kitMar 22, 2023

  • Sentry vulnerable to improper authorization on debug and artifact file downloads

    MediumCVSS 6.5No exploitEPSS 1%

    sentry · sentryJul 25, 2023

  • Sentry's superuser cleartext password leaked in logs

    MediumCVSS 6.5No exploitEPSS 0%

    sentry · sentryApr 18, 2024

  • Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

    MediumCVSS 6.1No exploitEPSS 1%

    sentry · sentry software development kitNov 9, 2023

  • Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocation

    MediumCVSS 5.5No exploitEPSS 1%

    sentry · sentryJul 1, 2025

  • Sentry allows unauthorized access to event data across organizational boundaries

    MediumCVSS 5.7No exploitEPSS 0%

    sentry · sentryMar 17, 2026

  • Sentry's improper error handling leaks Application Integration Client Secret

    MediumCVSS 5.3No exploitEPSS 1%

    sentry · sentryNov 22, 2024

  • SSRF in Sentry via Phabricator integration

    MediumCVSS 5.3No exploitEPSS 0%

    sentry · sentryFeb 8, 2024

  • Sentry vulnerable to stored Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    sentry · sentryJul 23, 2024

  • Symbolicator Server Side Request Forgery vulnerability

    MediumCVSS 4.3No exploitEPSS 1%

    sentry · symbolicatorNov 30, 2023

  • SSRF in symbolicator via invalid protocol

    MediumCVSS 4.3No exploitEPSS 0%

    sentry · symbolicatorDec 22, 2023

  • Improper authorization on deletion of user issue alert notifications in sentry

    MediumCVSS 4.3No exploitEPSS 0%

    sentry · sentrySep 17, 2024

  • Improper authorization on muting of alert rules in sentry

    MediumCVSS 4.3No exploitEPSS 0%

    sentry · sentrySep 17, 2024

  • Invite code reuse via cookie manipulation in sentry

    LowCVSS 3.7No exploitEPSS 0%

    sentry · sentryDec 9, 2022