Записи Securly
7 опубликованных записей вендора securly.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-798 Use of Hard-coded Credentials1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-916 Use of Password Hash With Insufficient Computational Effort1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2026-8888Proof of concept | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular exsecurly · securly · CWE-917 | Высокая7,5 | — | 0,6 % | 3 июн. 2026 г. |
30Наблюдать | CVE-2026-8879Эксплойта нет | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContensecurly · securly · CWE-829 | Высокая7,5 | — | 0,5 % | 3 июн. 2026 г. |
30Наблюдать | CVE-2026-8889Эксплойта нет | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matsecurly · securly · CWE-407 | Высокая7,5 | — | 0,3 % | 3 июн. 2026 г. |
30Наблюдать | CVE-2026-8878Эксплойта нет | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive securly · securly · CWE-326 | Высокая7,5 | — | 0,3 % | 3 июн. 2026 г. |
30Наблюдать | CVE-2026-8881Эксплойта нет | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption.securly · securly · CWE-916 | Высокая7,5 | — | 0,2 % | 3 июн. 2026 г. |
29Наблюдать | CVE-2026-8876Эксплойта нет | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js.securly · securly · CWE-798 | Высокая7,3 | — | 0,3 % | 3 июн. 2026 г. |
28Наблюдать | CVE-2026-8874Эксплойта нет | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTsecurly · securly · CWE-319 | Высокая7,1 | — | 0,2 % | 3 июн. 2026 г. |
- CVE-2026-888830Наблюдать
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular ex
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %securly · securly3 июн. 2026 г.
- CVE-2026-887930Наблюдать
Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerConten
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %securly · securly3 июн. 2026 г.
- CVE-2026-888930Наблюдать
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist mat
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %securly · securly3 июн. 2026 г.
- CVE-2026-887830Наблюдать
Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %securly · securly3 июн. 2026 г.
- CVE-2026-888130Наблюдать
Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %securly · securly3 июн. 2026 г.
- CVE-2026-887629Наблюдать
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %securly · securly3 июн. 2026 г.
- CVE-2026-887428Наблюдать
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTT
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %securly · securly3 июн. 2026 г.