Записи anuko
12 опубликованных записей вендора anuko.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 58,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-613 Insufficient Session Expiration1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-27422Proof of concept | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the sanuko · time tracker · CWE-613 | Критическая9,8 | — | 7,9 % | 16 нояб. 2020 г. |
39Наблюдать | CVE-2023-32306Эксплойта нет | Time Tracker has Blind SQL Injection Vulnerability in Reportsanuko · time tracker · CWE-89 | Критическая9,8 | — | 0,7 % | 12 мая 2023 г. |
39Наблюдать | CVE-2023-32308Эксплойта нет | SQL Injection Vulnerability in anuko timetrackeranuko · time tracker · CWE-89 | Критическая9,8 | — | 0,7 % | 15 мая 2023 г. |
37Наблюдать | CVE-2022-24707Proof of concept | SQL injection in anuko timetrackeranuko · time tracker · CWE-89 | Высокая8,8 | — | 7,2 % | 24 февр. 2022 г. |
36Наблюдать | CVE-2021-21352Эксплойта нет | Predictable tokens used for password resetsanuko · time tracker · CWE-330 | Критическая9,1 | — | 1,5 % | 2 мар. 2021 г. |
35Наблюдать | CVE-2021-43851Эксплойта нет | SQL injection vulnerability in anuko timetrackeranuko · time tracker · CWE-89 | Высокая8,8 | — | 1,2 % | 21 дек. 2021 г. |
32Наблюдать | CVE-2020-27423Proof of concept | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on anuko · time tracker · CWE-307 | Высокая7,5 | — | 6,4 % | 16 нояб. 2020 г. |
32Наблюдать | CVE-2021-29436Эксплойта нет | Cross site request forgery vulnerabilityanuko · time tracker · CWE-352 | Высокая8,1 | — | 0,5 % | 13 апр. 2021 г. |
30Наблюдать | CVE-2020-15255Proof of concept | CSV injection in Anuko Time Trackeranuko · time tracker · CWE-74 | Высокая7,3 | — | 3,5 % | 16 окт. 2020 г. |
24Наблюдать | CVE-2021-41139Эксплойта нет | Reflected XSS vulnerability in time.phpanuko · time tracker · CWE-79 | Средняя6,1 | — | 1,0 % | 13 окт. 2021 г. |
21Наблюдать | CVE-2022-24708Эксплойта нет | Stored XSS vulnerability in anuko/timetrackeranuko · time tracker · CWE-79 | Средняя5,4 | — | 0,6 % | 24 февр. 2022 г. |
21Наблюдать | CVE-2023-32066Эксплойта нет | Time Tracker has Stored XSS vulnerability in Week View pluginanuko · time tracker · CWE-79 | Средняя5,4 | — | 0,4 % | 9 мая 2023 г. |
- CVE-2020-2742241В плане
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s
КритическаяCVSS 9,8Proof of conceptEPSS 8 %anuko · time tracker16 нояб. 2020 г.
- CVE-2023-3230639Наблюдать
Time Tracker has Blind SQL Injection Vulnerability in Reports
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %anuko · time tracker12 мая 2023 г.
- CVE-2023-3230839Наблюдать
SQL Injection Vulnerability in anuko timetracker
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %anuko · time tracker15 мая 2023 г.
- CVE-2022-2470737Наблюдать
SQL injection in anuko timetracker
ВысокаяCVSS 8,8Proof of conceptEPSS 7 %anuko · time tracker24 февр. 2022 г.
- CVE-2021-2135236Наблюдать
Predictable tokens used for password resets
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %anuko · time tracker2 мар. 2021 г.
- CVE-2021-4385135Наблюдать
SQL injection vulnerability in anuko timetracker
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %anuko · time tracker21 дек. 2021 г.
- CVE-2020-2742332Наблюдать
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %anuko · time tracker16 нояб. 2020 г.
- CVE-2021-2943632Наблюдать
Cross site request forgery vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %anuko · time tracker13 апр. 2021 г.
- CVE-2020-1525530Наблюдать
CSV injection in Anuko Time Tracker
ВысокаяCVSS 7,3Proof of conceptEPSS 4 %anuko · time tracker16 окт. 2020 г.
- CVE-2021-4113924Наблюдать
Reflected XSS vulnerability in time.php
СредняяCVSS 6,1Эксплойта нетEPSS 1 %anuko · time tracker13 окт. 2021 г.
- CVE-2022-2470821Наблюдать
Stored XSS vulnerability in anuko/timetracker
СредняяCVSS 5,4Эксплойта нетEPSS 1 %anuko · time tracker24 февр. 2022 г.
- CVE-2023-3206621Наблюдать
Time Tracker has Stored XSS vulnerability in Week View plugin
СредняяCVSS 5,4Эксплойта нетEPSS 0 %anuko · time tracker9 мая 2023 г.