Записи rymcu
6 опубликованных записей вендора rymcu.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-862 Missing Authorization2
- CWE-863 Incorrect Authorization1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2023-51804Эксплойта нет | An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.ryrymcu · forest · CWE-918 | Высокая7,5 | — | 0,7 % | 12 янв. 2024 г. |
27Наблюдать | CVE-2025-12925Эксплойта нет | rymcu forest UserDicController.java deleteDic authorizationrymcu · forest · CWE-862 | Средняя6,9 | — | 0,4 % | 9 нояб. 2025 г. |
26Наблюдать | CVE-2025-63687Эксплойта нет | An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/serymcu · forest · CWE-863 | Средняя6,5 | — | 0,3 % | 7 нояб. 2025 г. |
21Наблюдать | CVE-2025-12924Эксплойта нет | rymcu forest BankController.java GlobalResult authorizationrymcu · forest · CWE-862 | Средняя5,3 | — | 0,3 % | 9 нояб. 2025 г. |
8Наблюдать | CVE-2026-2946Эксплойта нет | rymcu forest Article Content/Comments/Portfolio XssUtils.java XssUtils.replaceHtmlCode cross site scriptingrymcu · forest · CWE-79 | Низкая2,0 | — | 0,4 % | 22 февр. 2026 г. |
8Наблюдать | CVE-2026-2947Эксплойта нет | rymcu forest User Profile UserInfoController.java updateUserInfo cross site scriptingrymcu · forest · CWE-79 | Низкая2,0 | — | 0,4 % | 22 февр. 2026 г. |
- CVE-2023-5180430Наблюдать
An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.ry
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rymcu · forest12 янв. 2024 г.
- CVE-2025-1292527Наблюдать
rymcu forest UserDicController.java deleteDic authorization
СредняяCVSS 6,9Эксплойта нетEPSS 0 %rymcu · forest9 нояб. 2025 г.
- CVE-2025-6368726Наблюдать
An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/se
СредняяCVSS 6,5Эксплойта нетEPSS 0 %rymcu · forest7 нояб. 2025 г.
- CVE-2025-1292421Наблюдать
rymcu forest BankController.java GlobalResult authorization
СредняяCVSS 5,3Эксплойта нетEPSS 0 %rymcu · forest9 нояб. 2025 г.
- CVE-2026-29468Наблюдать
rymcu forest Article Content/Comments/Portfolio XssUtils.java XssUtils.replaceHtmlCode cross site scripting
НизкаяCVSS 2,0Эксплойта нетEPSS 0 %rymcu · forest22 февр. 2026 г.
- CVE-2026-29478Наблюдать
rymcu forest User Profile UserInfoController.java updateUserInfo cross site scripting
НизкаяCVSS 2,0Эксплойта нетEPSS 0 %rymcu · forest22 февр. 2026 г.