Записи alf
10 опубликованных записей вендора alf.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 20 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere1
- CWE-612 Improper Authorization of Index Containing Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-35482Эксплойта нет | alf.io has an Authenticated RCE via Extension Script Sandbox Escapealf · alf · CWE-863 | Критическая9,1 | — | 0,4 % | 2 июн. 2026 г. |
35Наблюдать | CVE-2023-2258Эксплойта нет | Improper Neutralization of Formula Elements in a CSV File in alfio-event/alf.ioalf · alf · CWE-1236 | Высокая8,8 | — | 0,9 % | 24 апр. 2023 г. |
35Наблюдать | CVE-2023-2260Эксплойта нет | Authorization Bypass Through User-Controlled Key in alfio-event/alf.ioalf · alf · CWE-639 | Высокая8,8 | — | 0,9 % | 24 апр. 2023 г. |
35Наблюдать | CVE-2024-25635Эксплойта нет | IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERSalf · alf · CWE-612 | Высокая8,8 | — | 0,7 % | 19 февр. 2024 г. |
30Наблюдать | CVE-2024-25628Эксплойта нет | Insufficient Session Expiration in alf.ioalf · alf · CWE-613 | Высокая7,6 | — | 0,4 % | 16 февр. 2024 г. |
28Наблюдать | CVE-2023-2259Эксплойта нет | Improper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.ioalf · alf · CWE-1336 | Высокая7,2 | — | 1,1 % | 24 апр. 2023 г. |
26Наблюдать | CVE-2024-25634Эксплойта нет | IDOR make user can read e-mail log sent by other eventsalf · alf · CWE-497 | Средняя6,5 | — | 0,7 % | 19 февр. 2024 г. |
26Наблюдать | CVE-2024-45299Эксплойта нет | alf.io's preloaded data as json is not escaped correctlyalf · alf · CWE-116 | Средняя6,5 | — | 0,7 % | 6 сент. 2024 г. |
23Наблюдать | CVE-2024-45300Эксплойта нет | Bypassing promo code limitations with race conditionsalf · alf · CWE-362 | Средняя5,9 | — | 0,4 % | 6 сент. 2024 г. |
19Наблюдать | CVE-2024-25627Эксплойта нет | Cross-Site Scripting (XSS) via File Upload in Alf.ioalf · alf · CWE-79 | Средняя4,8 | — | 0,4 % | 16 февр. 2024 г. |
- CVE-2026-3548236Наблюдать
alf.io has an Authenticated RCE via Extension Script Sandbox Escape
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %alf · alf2 июн. 2026 г.
- CVE-2023-225835Наблюдать
Improper Neutralization of Formula Elements in a CSV File in alfio-event/alf.io
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %alf · alf24 апр. 2023 г.
- CVE-2023-226035Наблюдать
Authorization Bypass Through User-Controlled Key in alfio-event/alf.io
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %alf · alf24 апр. 2023 г.
- CVE-2024-2563535Наблюдать
IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %alf · alf19 февр. 2024 г.
- CVE-2024-2562830Наблюдать
Insufficient Session Expiration in alf.io
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %alf · alf16 февр. 2024 г.
- CVE-2023-225928Наблюдать
Improper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.io
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %alf · alf24 апр. 2023 г.
- CVE-2024-2563426Наблюдать
IDOR make user can read e-mail log sent by other events
СредняяCVSS 6,5Эксплойта нетEPSS 1 %alf · alf19 февр. 2024 г.
- CVE-2024-4529926Наблюдать
alf.io's preloaded data as json is not escaped correctly
СредняяCVSS 6,5Эксплойта нетEPSS 1 %alf · alf6 сент. 2024 г.
- CVE-2024-4530023Наблюдать
Bypassing promo code limitations with race conditions
СредняяCVSS 5,9Эксплойта нетEPSS 0 %alf · alf6 сент. 2024 г.
- CVE-2024-2562719Наблюдать
Cross-Site Scripting (XSS) via File Upload in Alf.io
СредняяCVSS 4,8Эксплойта нетEPSS 0 %alf · alf16 февр. 2024 г.