Записи ethyca
20 опубликованных записей вендора ethyca.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-38537Proof of concept | Inclusion of Untrusted polyfill.io Code Vulnerability in fides.jsethyca · fides · CWE-829 | Критическая9,8 | — | 1,4 % | 2 июл. 2024 г. |
36Наблюдать | CVE-2023-48224Эксплойта нет | Cryptographically Weak Generation of One-Time Codes for Identity Verification in ethyca-fidesethyca · fides · CWE-338 | Критическая9,1 | — | 1,0 % | 15 нояб. 2023 г. |
34Наблюдать | CVE-2025-57817Эксплойта нет | Fides Webserver API is Vulnerable to OAuth Client Privilege Escalationethyca · fides · CWE-862 | Высокая8,6 | — | 0,4 % | 8 сент. 2025 г. |
30Наблюдать | CVE-2023-36827Эксплойта нет | Fides vulnerable to Path Traversal in Webserver APIethyca · fides · CWE-22 | Высокая7,5 | — | 1,5 % | 5 июл. 2023 г. |
28Наблюдать | CVE-2024-45053Эксплойта нет | Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engineethyca · fides · CWE-1336 | Высокая7,2 | — | 1,3 % | 4 сент. 2024 г. |
28Наблюдать | CVE-2023-41319Эксплойта нет | Remote Code Execution in Custom Integration Upload in Fidesethyca · fides · CWE-94 | Высокая7,2 | — | 0,9 % | 6 сент. 2023 г. |
28Наблюдать | CVE-2023-46124Эксплойта нет | Server-Side Request Forgery Vulnerability in Custom Integration Uploadethyca · fides · CWE-918 | Высокая7,2 | — | 0,7 % | 25 окт. 2023 г. |
26Наблюдать | CVE-2023-46125Эксплойта нет | Fides Information Disclosure Vulnerability in Config API Endpointethyca · fides · CWE-200 | Средняя6,5 | — | 0,7 % | 25 окт. 2023 г. |
26Наблюдать | CVE-2024-35189Эксплойта нет | Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in Fidesethyca · fides · CWE-200 | Средняя6,5 | — | 0,6 % | 30 мая 2024 г. |
25Наблюдать | CVE-2025-57816Эксплойта нет | Fides Webserver API Rate Limiting Vulnerability in Proxied Environmentsethyca · fides · CWE-799 | Средняя6,3 | — | 0,4 % | 8 сент. 2025 г. |
24Наблюдать | CVE-2023-47114Эксплойта нет | Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packagesethyca · fides · CWE-79 | Средняя6,1 | — | 0,6 % | 8 нояб. 2023 г. |
21Наблюдать | CVE-2024-31223Proof of concept | Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URLethyca · fides · CWE-497 | Средняя5,3 | — | 1,1 % | 3 июл. 2024 г. |
21Наблюдать | CVE-2023-46126Эксплойта нет | Fides JavaScript Injection Vulnerability in Privacy Center URLethyca · fides · CWE-79 | Средняя5,4 | — | 0,6 % | 25 окт. 2023 г. |
21Наблюдать | CVE-2024-45052Эксплойта нет | Fides Webserver Authentication Timing-Based Username Enumeration Vulnerabilityethyca · fides · CWE-208 | Средняя5,3 | — | 0,6 % | 4 сент. 2024 г. |
19Наблюдать | CVE-2023-37481Эксплойта нет | Fides Webserver Vulnerable to SVG Bomb File Uploadsethyca · fides · CWE-400 | Средняя4,9 | — | 0,7 % | 18 июл. 2023 г. |
19Наблюдать | CVE-2023-37480Эксплойта нет | Fides Webserver Vulnerable to Zip Bomb File Uploadsethyca · fides · CWE-400 | Средняя4,9 | — | 0,7 % | 18 июл. 2023 г. |
13Наблюдать | CVE-2024-34715Эксплойта нет | Partial Password Exposure Vulnerability in Fides Webserver Logsethyca · fides · CWE-116 | Низкая3,3 | — | 0,3 % | 29 мая 2024 г. |
8Наблюдать | CVE-2024-52008Эксплойта нет | Password Policy Bypass Vulnerability in Fides Webserverethyca · fides · CWE-602 | Низкая2,0 | — | 0,6 % | 26 нояб. 2024 г. |
6Наблюдать | CVE-2025-57766Эксплойта нет | Fides's Admin UI User Password Change Does Not Invalidate Current Sessionethyca · fides · CWE-613 | Низкая1,7 | — | 0,3 % | 8 сент. 2025 г. |
6Наблюдать | CVE-2025-57815Эксплойта нет | Fides Lacks Brute-Force Protections on Authentication Endpointsethyca · fides · CWE-307 | Низкая1,7 | — | 0,3 % | 8 сент. 2025 г. |
- CVE-2024-3853739Наблюдать
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
КритическаяCVSS 9,8Proof of conceptEPSS 1 %ethyca · fides2 июл. 2024 г.
- CVE-2023-4822436Наблюдать
Cryptographically Weak Generation of One-Time Codes for Identity Verification in ethyca-fides
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %ethyca · fides15 нояб. 2023 г.
- CVE-2025-5781734Наблюдать
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %ethyca · fides8 сент. 2025 г.
- CVE-2023-3682730Наблюдать
Fides vulnerable to Path Traversal in Webserver API
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ethyca · fides5 июл. 2023 г.
- CVE-2024-4505328Наблюдать
Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ethyca · fides4 сент. 2024 г.
- CVE-2023-4131928Наблюдать
Remote Code Execution in Custom Integration Upload in Fides
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ethyca · fides6 сент. 2023 г.
- CVE-2023-4612428Наблюдать
Server-Side Request Forgery Vulnerability in Custom Integration Upload
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ethyca · fides25 окт. 2023 г.
- CVE-2023-4612526Наблюдать
Fides Information Disclosure Vulnerability in Config API Endpoint
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ethyca · fides25 окт. 2023 г.
- CVE-2024-3518926Наблюдать
Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in Fides
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ethyca · fides30 мая 2024 г.
- CVE-2025-5781625Наблюдать
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
СредняяCVSS 6,3Эксплойта нетEPSS 0 %ethyca · fides8 сент. 2025 г.
- CVE-2023-4711424Наблюдать
Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ethyca · fides8 нояб. 2023 г.
- CVE-2024-3122321Наблюдать
Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
СредняяCVSS 5,3Proof of conceptEPSS 1 %ethyca · fides3 июл. 2024 г.
- CVE-2023-4612621Наблюдать
Fides JavaScript Injection Vulnerability in Privacy Center URL
СредняяCVSS 5,4Эксплойта нетEPSS 1 %ethyca · fides25 окт. 2023 г.
- CVE-2024-4505221Наблюдать
Fides Webserver Authentication Timing-Based Username Enumeration Vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ethyca · fides4 сент. 2024 г.
- CVE-2023-3748119Наблюдать
Fides Webserver Vulnerable to SVG Bomb File Uploads
СредняяCVSS 4,9Эксплойта нетEPSS 1 %ethyca · fides18 июл. 2023 г.
- CVE-2023-3748019Наблюдать
Fides Webserver Vulnerable to Zip Bomb File Uploads
СредняяCVSS 4,9Эксплойта нетEPSS 1 %ethyca · fides18 июл. 2023 г.
- CVE-2024-3471513Наблюдать
Partial Password Exposure Vulnerability in Fides Webserver Logs
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %ethyca · fides29 мая 2024 г.
- CVE-2024-520088Наблюдать
Password Policy Bypass Vulnerability in Fides Webserver
НизкаяCVSS 2,0Эксплойта нетEPSS 1 %ethyca · fides26 нояб. 2024 г.
- CVE-2025-577666Наблюдать
Fides's Admin UI User Password Change Does Not Invalidate Current Session
НизкаяCVSS 1,7Эксплойта нетEPSS 0 %ethyca · fides8 сент. 2025 г.
- CVE-2025-578156Наблюдать
Fides Lacks Brute-Force Protections on Authentication Endpoints
НизкаяCVSS 1,7Эксплойта нетEPSS 0 %ethyca · fides8 сент. 2025 г.