Записи plotly
4 опубликованных записей вендора plotly.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-46308Эксплойта нет | In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.plotly · plotly.js · CWE-1321 | Критическая9,8 | — | 0,9 % | 3 янв. 2024 г. |
32Наблюдать | CVE-2026-55810Эксплойта нет | Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050plotly · plotly.js graphing · CWE-915 | Высокая8,1 | — | 0,4 % | 10 июл. 2026 г. |
24Наблюдать | CVE-2017-1000006Эксплойта нет | Plotly, Inc.plotly · plotly.js · CWE-79 | Средняя6,1 | — | 0,9 % | 17 июл. 2017 г. |
21Наблюдать | CVE-2024-21485Proof of concept | Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the packaplotly · dash · CWE-79 | Средняя5,4 | — | 1,5 % | 2 февр. 2024 г. |
- CVE-2023-4630839Наблюдать
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %plotly · plotly.js3 янв. 2024 г.
- CVE-2026-5581032Наблюдать
Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %plotly · plotly.js graphing10 июл. 2026 г.
- CVE-2017-100000624Наблюдать
Plotly, Inc.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %plotly · plotly.js17 июл. 2017 г.
- CVE-2024-2148521Наблюдать
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the packa
СредняяCVSS 5,4Proof of conceptEPSS 1 %plotly · dash2 февр. 2024 г.