heartcombo kayıtları
heartcombo üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2015-8314İstismar yok | The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persisheartcombo · devise · CWE-312 | Yüksek7,5 | — | %0,6 | 12 Ara 2023 |
24İzleyin | CVE-2026-32700İstismar yok | Devise has a confirmable "change email" race condition that permits user to confirm email they have no access toheartcombo · devise · CWE-362 | Orta6,0 | — | %0,3 | 18 Mar 2026 |
24İzleyin | CVE-2026-40295İstismar yok | Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handlerheartcombo · devise · CWE-601 | Orta6,1 | — | %0,3 | 22 May 2026 |
- CVE-2015-831430İzleyin
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persis
YüksekCVSS 7,5İstismar yokEPSS %1heartcombo · devise12 Ara 2023
- CVE-2026-3270024İzleyin
Devise has a confirmable "change email" race condition that permits user to confirm email they have no access to
OrtaCVSS 6,0İstismar yokEPSS %0heartcombo · devise18 Mar 2026
- CVE-2026-4029524İzleyin
Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
OrtaCVSS 6,1İstismar yokEPSS %0heartcombo · devise22 May 2026