okfn kayıtları
okfn üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %85,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-269 Improper Privilege Management1
- CWE-295 Improper Certificate Validation1
- CWE-330 Use of Insufficiently Random Values1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-32321İstismar yok | CKAN remote code execution and private information access via crafted resource idsokfn · ckan · CWE-20 | Kritik9,8 | — | %1,7 | 26 May 2023 |
35İzleyin | CVE-2023-32696İstismar yok | Excessive permissions for ckan userokfn · ckan · CWE-269 | Yüksek8,8 | — | %0,8 | 30 May 2023 |
35İzleyin | CVE-2022-43685İstismar yok | CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request.okfn · ckan · CWE-862 | Yüksek8,8 | — | %0,7 | 21 Kas 2022 |
34İzleyin | CVE-2026-42031Kavram kanıtı | CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`okfn · ckan · CWE-89 | Yüksek8,3 | — | %2,2 | 13 May 2026 |
30İzleyin | CVE-2023-22746İstismar yok | CKAN is vulnerable to session secret shared across instances using Docker imagesokfn · ckan · CWE-330 | Yüksek7,5 | — | %0,7 | 3 Şub 2023 |
26İzleyin | CVE-2023-50248İstismar yok | CKAN out of memory error when submitting the dataset form with a specially-crafted fieldokfn · ckan · CWE-130 | Orta6,5 | — | %0,6 | 13 Ara 2023 |
26İzleyin | CVE-2026-42032İstismar yok | CKAN: Unauthenticated Authorization Bypass in `datastore_search_sql`okfn · ckan · CWE-863 | Orta6,7 | — | %0,4 | 13 May 2026 |
26İzleyin | CVE-2024-43371İstismar yok | Potential access to sensitive URLs via CKAN extensions (SSRF)okfn · ckan · CWE-918 | Orta6,5 | — | %0,4 | 21 Ağu 2024 |
26İzleyin | CVE-2026-41132İstismar yok | CKAN: No certificate validation on STMP connectionokfn · ckan · CWE-295 | Orta6,6 | — | %0,2 | 13 May 2026 |
24İzleyin | CVE-2024-41675İstismar yok | CKAN has a Cross-site Scripting vector in the Datatables view pluginokfn · ckan · CWE-79 | Orta6,1 | — | %0,4 | 21 Ağu 2024 |
24İzleyin | CVE-2026-41255İstismar yok | CKAN: CSRF exemption primed by anonymous requestsokfn · ckan · CWE-352 | Orta6,1 | — | %0,1 | 13 May 2026 |
21İzleyin | CVE-2021-25967İstismar yok | CKAN - Stored Cross-Site Scripting (XSS) via SVG File Uploadokfn · ckan · CWE-79 | Orta5,4 | — | %0,5 | 1 Ara 2021 |
21İzleyin | CVE-2024-27097İstismar yok | Potential log injection in reset user endpoint in ckanokfn · ckan · CWE-532 | Orta5,3 | — | %0,4 | 13 Mar 2024 |
21İzleyin | CVE-2024-41674İstismar yok | CKAN may leak Solr credentials via error message in package_search actionokfn · ckan · CWE-209 | Orta5,3 | — | %0,4 | 21 Ağu 2024 |
- CVE-2023-3232140Planlayın
CKAN remote code execution and private information access via crafted resource ids
KritikCVSS 9,8İstismar yokEPSS %2okfn · ckan26 May 2023
- CVE-2023-3269635İzleyin
Excessive permissions for ckan user
YüksekCVSS 8,8İstismar yokEPSS %1okfn · ckan30 May 2023
- CVE-2022-4368535İzleyin
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request.
YüksekCVSS 8,8İstismar yokEPSS %1okfn · ckan21 Kas 2022
- CVE-2026-4203134İzleyin
CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
YüksekCVSS 8,3Kavram kanıtıEPSS %2okfn · ckan13 May 2026
- CVE-2023-2274630İzleyin
CKAN is vulnerable to session secret shared across instances using Docker images
YüksekCVSS 7,5İstismar yokEPSS %1okfn · ckan3 Şub 2023
- CVE-2023-5024826İzleyin
CKAN out of memory error when submitting the dataset form with a specially-crafted field
OrtaCVSS 6,5İstismar yokEPSS %1okfn · ckan13 Ara 2023
- CVE-2026-4203226İzleyin
CKAN: Unauthenticated Authorization Bypass in `datastore_search_sql`
OrtaCVSS 6,7İstismar yokEPSS %0okfn · ckan13 May 2026
- CVE-2024-4337126İzleyin
Potential access to sensitive URLs via CKAN extensions (SSRF)
OrtaCVSS 6,5İstismar yokEPSS %0okfn · ckan21 Ağu 2024
- CVE-2026-4113226İzleyin
CKAN: No certificate validation on STMP connection
OrtaCVSS 6,6İstismar yokEPSS %0okfn · ckan13 May 2026
- CVE-2024-4167524İzleyin
CKAN has a Cross-site Scripting vector in the Datatables view plugin
OrtaCVSS 6,1İstismar yokEPSS %0okfn · ckan21 Ağu 2024
- CVE-2026-4125524İzleyin
CKAN: CSRF exemption primed by anonymous requests
OrtaCVSS 6,1İstismar yokEPSS %0okfn · ckan13 May 2026
- CVE-2021-2596721İzleyin
CKAN - Stored Cross-Site Scripting (XSS) via SVG File Upload
OrtaCVSS 5,4İstismar yokEPSS %1okfn · ckan1 Ara 2021
- CVE-2024-2709721İzleyin
Potential log injection in reset user endpoint in ckan
OrtaCVSS 5,3İstismar yokEPSS %0okfn · ckan13 Mar 2024
- CVE-2024-4167421İzleyin
CKAN may leak Solr credentials via error message in package_search action
OrtaCVSS 5,3İstismar yokEPSS %0okfn · ckan21 Ağu 2024