alf kayıtları
alf üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere1
- CWE-612 Improper Authorization of Index Containing Sensitive Information1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-35482İstismar yok | alf.io has an Authenticated RCE via Extension Script Sandbox Escapealf · alf · CWE-863 | Kritik9,1 | — | %0,4 | 2 Haz 2026 |
35İzleyin | CVE-2023-2258İstismar yok | Improper Neutralization of Formula Elements in a CSV File in alfio-event/alf.ioalf · alf · CWE-1236 | Yüksek8,8 | — | %0,9 | 24 Nis 2023 |
35İzleyin | CVE-2023-2260İstismar yok | Authorization Bypass Through User-Controlled Key in alfio-event/alf.ioalf · alf · CWE-639 | Yüksek8,8 | — | %0,9 | 24 Nis 2023 |
35İzleyin | CVE-2024-25635İstismar yok | IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERSalf · alf · CWE-612 | Yüksek8,8 | — | %0,7 | 19 Şub 2024 |
30İzleyin | CVE-2024-25628İstismar yok | Insufficient Session Expiration in alf.ioalf · alf · CWE-613 | Yüksek7,6 | — | %0,4 | 16 Şub 2024 |
28İzleyin | CVE-2023-2259İstismar yok | Improper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.ioalf · alf · CWE-1336 | Yüksek7,2 | — | %1,1 | 24 Nis 2023 |
26İzleyin | CVE-2024-25634İstismar yok | IDOR make user can read e-mail log sent by other eventsalf · alf · CWE-497 | Orta6,5 | — | %0,7 | 19 Şub 2024 |
26İzleyin | CVE-2024-45299İstismar yok | alf.io's preloaded data as json is not escaped correctlyalf · alf · CWE-116 | Orta6,5 | — | %0,7 | 6 Eyl 2024 |
23İzleyin | CVE-2024-45300İstismar yok | Bypassing promo code limitations with race conditionsalf · alf · CWE-362 | Orta5,9 | — | %0,4 | 6 Eyl 2024 |
19İzleyin | CVE-2024-25627İstismar yok | Cross-Site Scripting (XSS) via File Upload in Alf.ioalf · alf · CWE-79 | Orta4,8 | — | %0,4 | 16 Şub 2024 |
- CVE-2026-3548236İzleyin
alf.io has an Authenticated RCE via Extension Script Sandbox Escape
KritikCVSS 9,1İstismar yokEPSS %0alf · alf2 Haz 2026
- CVE-2023-225835İzleyin
Improper Neutralization of Formula Elements in a CSV File in alfio-event/alf.io
YüksekCVSS 8,8İstismar yokEPSS %1alf · alf24 Nis 2023
- CVE-2023-226035İzleyin
Authorization Bypass Through User-Controlled Key in alfio-event/alf.io
YüksekCVSS 8,8İstismar yokEPSS %1alf · alf24 Nis 2023
- CVE-2024-2563535İzleyin
IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
YüksekCVSS 8,8İstismar yokEPSS %1alf · alf19 Şub 2024
- CVE-2024-2562830İzleyin
Insufficient Session Expiration in alf.io
YüksekCVSS 7,6İstismar yokEPSS %0alf · alf16 Şub 2024
- CVE-2023-225928İzleyin
Improper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.io
YüksekCVSS 7,2İstismar yokEPSS %1alf · alf24 Nis 2023
- CVE-2024-2563426İzleyin
IDOR make user can read e-mail log sent by other events
OrtaCVSS 6,5İstismar yokEPSS %1alf · alf19 Şub 2024
- CVE-2024-4529926İzleyin
alf.io's preloaded data as json is not escaped correctly
OrtaCVSS 6,5İstismar yokEPSS %1alf · alf6 Eyl 2024
- CVE-2024-4530023İzleyin
Bypassing promo code limitations with race conditions
OrtaCVSS 5,9İstismar yokEPSS %0alf · alf6 Eyl 2024
- CVE-2024-2562719İzleyin
Cross-Site Scripting (XSS) via File Upload in Alf.io
OrtaCVSS 4,8İstismar yokEPSS %0alf · alf16 Şub 2024