Записи thecodingmachine
22 опубликованных записей вендора thecodingmachine.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 68,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-73 External Control of File Name or Path2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-1333 Inefficient Regular Expression Complexity1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-13450Эксплойта нет | A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writabthecodingmachine · gotenberg · CWE-22 | Критическая9,8 | — | 5,8 % | 7 янв. 2021 г. |
40В плане | CVE-2026-42589Proof of concept | Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injectionthecodingmachine · gotenberg · CWE-78 | Критическая9,8 | — | 3,7 % | 14 мая 2026 г. |
40В плане | CVE-2020-13451Эксплойта нет | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice cothecodingmachine · gotenberg · CWE-459 | Критическая9,8 | — | 3,2 % | 7 янв. 2021 г. |
40В плане | CVE-2020-13452Эксплойта нет | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, thecodingmachine · gotenberg · CWE-276 | Критическая9,8 | — | 2,9 % | 7 янв. 2021 г. |
38Наблюдать | CVE-2026-42596Proof of concept | Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhookthecodingmachine · gotenberg · CWE-918 | Критическая9,4 | — | 1,8 % | 14 мая 2026 г. |
37Наблюдать | CVE-2026-40281Proof of concept | Gotenberg vulnerable to argument injection via newlines in ExifTool metadata valuesthecodingmachine · gotenberg · CWE-88 | Критическая9,1 | — | 2,1 % | 6 мая 2026 г. |
34Наблюдать | CVE-2026-35458Эксплойта нет | Gotenberg has a ReDoS via extraHttpHeaders scope featurethecodingmachine · gotenberg · CWE-1333 | Высокая8,7 | — | 0,6 % | 7 апр. 2026 г. |
34Наблюдать | CVE-2026-42595Эксплойта нет | Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypassthecodingmachine · gotenberg · CWE-918 | Высокая8,6 | — | 0,4 % | 14 мая 2026 г. |
32Наблюдать | CVE-2026-40280Proof of concept | Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-liststhecodingmachine · gotenberg · CWE-918 | Высокая7,8 | — | 2,1 % | 5 мая 2026 г. |
32Наблюдать | CVE-2026-40893Эксплойта нет | Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Movethecodingmachine · gotenberg · CWE-73 | Высокая8,2 | — | 0,5 % | 14 мая 2026 г. |
32Наблюдать | CVE-2026-42590Эксплойта нет | Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklistthecodingmachine · gotenberg · CWE-184 | Высокая8,2 | — | 0,4 % | 14 мая 2026 г. |
32Наблюдать | CVE-2026-42591Эксплойта нет | Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8thecodingmachine · gotenberg · CWE-918 | Высокая8,2 | — | 0,3 % | 14 мая 2026 г. |
31Наблюдать | CVE-2020-13449Эксплойта нет | A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.thecodingmachine · gotenberg · CWE-22 | Высокая7,5 | — | 5,0 % | 7 янв. 2021 г. |
31Наблюдать | CVE-2020-14160Эксплойта нет | An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able tthecodingmachine · gotenberg · CWE-918 | Высокая7,5 | — | 1,7 % | 26 авг. 2021 г. |
31Наблюдать | CVE-2026-27018Proof of concept | Gotenberg: Chromium deny-list bypass via case-insensitive URL schemethecodingmachine · gotenberg · CWE-22 | Высокая7,8 | — | 1,6 % | 30 мар. 2026 г. |
30Наблюдать | CVE-2026-42594Эксплойта нет | Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutinethecodingmachine · gotenberg · CWE-362 | Высокая7,5 | — | 0,4 % | 14 мая 2026 г. |
27Наблюдать | CVE-2026-39383Эксплойта нет | Gotenberg unauthenticated blind SSRF via unfiltered webhook URLthecodingmachine · gotenberg · CWE-918 | Средняя6,9 | — | 0,3 % | 5 мая 2026 г. |
24Наблюдать | CVE-2020-14161Эксплойта нет | It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.thecodingmachine · gotenberg · CWE-79 | Средняя6,1 | — | 0,9 % | 26 авг. 2021 г. |
23Наблюдать | CVE-2026-42597Эксплойта нет | Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// schemethecodingmachine · gotenberg · CWE-73 | Средняя5,9 | — | 0,4 % | 14 мая 2026 г. |
21Наблюдать | CVE-2021-23345Эксплойта нет | Server-side Request Forgery (SSRF)thecodingmachine · gotenberg · CWE-918 | Средняя5,3 | — | 1,1 % | 26 февр. 2021 г. |
21Наблюдать | CVE-2026-42593Эксплойта нет | Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routesthecodingmachine · gotenberg · CWE-22 | Средняя5,3 | — | 0,4 % | 14 мая 2026 г. |
21Наблюдать | CVE-2026-42592Эксплойта нет | Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routesthecodingmachine · gotenberg · CWE-367 | Средняя5,3 | — | 0,2 % | 14 мая 2026 г. |
- CVE-2020-1345041В плане
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writab
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %thecodingmachine · gotenberg7 янв. 2021 г.
- CVE-2026-4258940В плане
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
КритическаяCVSS 9,8Proof of conceptEPSS 4 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2020-1345140В плане
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thecodingmachine · gotenberg7 янв. 2021 г.
- CVE-2020-1345240В плане
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thecodingmachine · gotenberg7 янв. 2021 г.
- CVE-2026-4259638Наблюдать
Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
КритическаяCVSS 9,4Proof of conceptEPSS 2 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2026-4028137Наблюдать
Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values
КритическаяCVSS 9,1Proof of conceptEPSS 2 %thecodingmachine · gotenberg6 мая 2026 г.
- CVE-2026-3545834Наблюдать
Gotenberg has a ReDoS via extraHttpHeaders scope feature
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %thecodingmachine · gotenberg7 апр. 2026 г.
- CVE-2026-4259534Наблюдать
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2026-4028032Наблюдать
Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %thecodingmachine · gotenberg5 мая 2026 г.
- CVE-2026-4089332Наблюдать
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2026-4259032Наблюдать
Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2026-4259132Наблюдать
Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2020-1344931Наблюдать
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %thecodingmachine · gotenberg7 янв. 2021 г.
- CVE-2020-1416031Наблюдать
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %thecodingmachine · gotenberg26 авг. 2021 г.
- CVE-2026-2701831Наблюдать
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %thecodingmachine · gotenberg30 мар. 2026 г.
- CVE-2026-4259430Наблюдать
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2026-3938327Наблюдать
Gotenberg unauthenticated blind SSRF via unfiltered webhook URL
СредняяCVSS 6,9Эксплойта нетEPSS 0 %thecodingmachine · gotenberg5 мая 2026 г.
- CVE-2020-1416124Наблюдать
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %thecodingmachine · gotenberg26 авг. 2021 г.
- CVE-2026-4259723Наблюдать
Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
СредняяCVSS 5,9Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2021-2334521Наблюдать
Server-side Request Forgery (SSRF)
СредняяCVSS 5,3Эксплойта нетEPSS 1 %thecodingmachine · gotenberg26 февр. 2021 г.
- CVE-2026-4259321Наблюдать
Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
СредняяCVSS 5,3Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.
- CVE-2026-4259221Наблюдать
Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
СредняяCVSS 5,3Эксплойта нетEPSS 0 %thecodingmachine · gotenberg14 мая 2026 г.