Записи dradisframework
6 опубликованных записей вендора dradisframework.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 16,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1230 Exposure of Sensitive Information Through Metadata1
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
26Наблюдать | CVE-2019-19946Эксплойта нет | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.dradisframework · dradis · CWE-639 | Средняя6,5 | — | 1,2 % | 16 мар. 2020 г. |
23Наблюдать | CVE-2022-30028Эксплойта нет | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.dradisframework · dradis · CWE-362 | Средняя5,9 | — | 0,5 % | 24 июн. 2022 г. |
21Наблюдать | CVE-2019-5925Эксплойта нет | Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3dradisframework · dradis · CWE-79 | Средняя5,4 | — | 0,8 % | 12 мар. 2019 г. |
21Наблюдать | CVE-2023-31223Эксплойта нет | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.dradisframework · dradis · CWE-79 | Средняя5,4 | — | 0,5 % | 25 апр. 2023 г. |
17Наблюдать | CVE-2023-50786Эксплойта нет | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.dradisframework · dradis · CWE-294 | Средняя4,3 | — | 0,3 % | 5 июл. 2025 г. |
17Наблюдать | CVE-2023-50458Эксплойта нет | In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.dradisframework · dradis · CWE-1230 | Средняя4,3 | — | 0,2 % | 10 июл. 2025 г. |
- CVE-2019-1994626Наблюдать
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %dradisframework · dradis16 мар. 2020 г.
- CVE-2022-3002823Наблюдать
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %dradisframework · dradis24 июн. 2022 г.
- CVE-2019-592521Наблюдать
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dradisframework · dradis12 мар. 2019 г.
- CVE-2023-3122321Наблюдать
Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dradisframework · dradis25 апр. 2023 г.
- CVE-2023-5078617Наблюдать
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %dradisframework · dradis5 июл. 2025 г.
- CVE-2023-5045817Наблюдать
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %dradisframework · dradis10 июл. 2025 г.