İçeriğe atla
Noroxi

alf kayıtları

alf üreticisine ait 10 yayımlanmış kayıt.

Tüm kayıtlar

10 kayıt
  • CVE-2026-35482
    36İzleyin

    alf.io has an Authenticated RCE via Extension Script Sandbox Escape

    KritikCVSS 9,1İstismar yokEPSS %0

    alf · alf2 Haz 2026

  • CVE-2023-2258
    35İzleyin

    Improper Neutralization of Formula Elements in a CSV File in alfio-event/alf.io

    YüksekCVSS 8,8İstismar yokEPSS %1

    alf · alf24 Nis 2023

  • CVE-2023-2260
    35İzleyin

    Authorization Bypass Through User-Controlled Key in alfio-event/alf.io

    YüksekCVSS 8,8İstismar yokEPSS %1

    alf · alf24 Nis 2023

  • CVE-2024-25635
    35İzleyin

    IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS

    YüksekCVSS 8,8İstismar yokEPSS %1

    alf · alf19 Şub 2024

  • CVE-2024-25628
    30İzleyin

    Insufficient Session Expiration in alf.io

    YüksekCVSS 7,6İstismar yokEPSS %0

    alf · alf16 Şub 2024

  • CVE-2023-2259
    28İzleyin

    Improper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.io

    YüksekCVSS 7,2İstismar yokEPSS %1

    alf · alf24 Nis 2023

  • CVE-2024-25634
    26İzleyin

    IDOR make user can read e-mail log sent by other events

    OrtaCVSS 6,5İstismar yokEPSS %1

    alf · alf19 Şub 2024

  • CVE-2024-45299
    26İzleyin

    alf.io's preloaded data as json is not escaped correctly

    OrtaCVSS 6,5İstismar yokEPSS %1

    alf · alf6 Eyl 2024

  • CVE-2024-45300
    23İzleyin

    Bypassing promo code limitations with race conditions

    OrtaCVSS 5,9İstismar yokEPSS %0

    alf · alf6 Eyl 2024

  • CVE-2024-25627
    19İzleyin

    Cross-Site Scripting (XSS) via File Upload in Alf.io

    OrtaCVSS 4,8İstismar yokEPSS %0

    alf · alf16 Şub 2024