Записи ToolJet
11 опубликованных записей вендора tooljet.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 18,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-269 Improper Privilege Management1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2022-23067Эксплойта нет | ToolJet - Token Leakage via Referer Headertooljet · tooljet · CWE-200 | Высокая8,8 | — | 1,3 % | 18 мая 2022 г. |
35Наблюдать | CVE-2022-2631Эксплойта нет | Improper Access Control in tooljet/tooljettooljet · tooljet · CWE-284 | Высокая8,8 | — | 1,2 % | 2 авг. 2022 г. |
35Наблюдать | CVE-2022-3019Эксплойта нет | Improper Access Control in tooljet/tooljettooljet · tooljet · CWE-284 | Высокая8,8 | — | 0,9 % | 29 авг. 2022 г. |
35Наблюдать | CVE-2026-54344Эксплойта нет | ToolJet GitHub Actions comment body shell injection exposes deployment secretstooljet · tooljet · CWE-78 | Высокая8,8 | — | 0,4 % | 8 июл. 2026 г. |
32Наблюдать | CVE-2022-2037Эксплойта нет | Excessive Attack Surface in tooljet/tooljettooljet · tooljet · CWE-1125 | Высокая8,0 | — | 1,1 % | 9 июн. 2022 г. |
30Наблюдать | CVE-2022-27978Эксплойта нет | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP requestooljet · tooljet · CWE-755 | Высокая7,5 | — | 1,0 % | 26 апр. 2023 г. |
30Наблюдать | CVE-2022-3422Эксплойта нет | Improper Privilege Management in tooljet/tooljettooljet · tooljet · CWE-269 | Высокая7,5 | — | 0,9 % | 7 окт. 2022 г. |
26Наблюдать | CVE-2022-4111Эксплойта нет | Improper Validation of Specified Quantity in Input in tooljet/tooljettooljet · tooljet · CWE-1284 | Средняя6,5 | — | 0,8 % | 21 нояб. 2022 г. |
21Наблюдать | CVE-2022-23068Эксплойта нет | ToolJet - HTML Injection in Invite New Usertooljet · tooljet · CWE-74 | Средняя5,4 | — | 0,6 % | 18 мая 2022 г. |
21Наблюдать | CVE-2022-27979Эксплойта нет | A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadtooljet · tooljet · CWE-79 | Средняя5,4 | — | 0,5 % | 26 апр. 2023 г. |
19Наблюдать | CVE-2022-3348Эксплойта нет | Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljettooljet · tooljet · CWE-200 | Средняя4,9 | — | 1,0 % | 28 сент. 2022 г. |
- CVE-2022-2306735Наблюдать
ToolJet - Token Leakage via Referer Header
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %tooljet · tooljet18 мая 2022 г.
- CVE-2022-263135Наблюдать
Improper Access Control in tooljet/tooljet
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %tooljet · tooljet2 авг. 2022 г.
- CVE-2022-301935Наблюдать
Improper Access Control in tooljet/tooljet
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %tooljet · tooljet29 авг. 2022 г.
- CVE-2026-5434435Наблюдать
ToolJet GitHub Actions comment body shell injection exposes deployment secrets
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %tooljet · tooljet8 июл. 2026 г.
- CVE-2022-203732Наблюдать
Excessive Attack Surface in tooljet/tooljet
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %tooljet · tooljet9 июн. 2022 г.
- CVE-2022-2797830Наблюдать
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP reques
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %tooljet · tooljet26 апр. 2023 г.
- CVE-2022-342230Наблюдать
Improper Privilege Management in tooljet/tooljet
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %tooljet · tooljet7 окт. 2022 г.
- CVE-2022-411126Наблюдать
Improper Validation of Specified Quantity in Input in tooljet/tooljet
СредняяCVSS 6,5Эксплойта нетEPSS 1 %tooljet · tooljet21 нояб. 2022 г.
- CVE-2022-2306821Наблюдать
ToolJet - HTML Injection in Invite New User
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tooljet · tooljet18 мая 2022 г.
- CVE-2022-2797921Наблюдать
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tooljet · tooljet26 апр. 2023 г.
- CVE-2022-334819Наблюдать
Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljet
СредняяCVSS 4,9Эксплойта нетEPSS 1 %tooljet · tooljet28 сент. 2022 г.