phoenixframework kayıtları
phoenixframework üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-56811İstismar yok | Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of servicephoenixframework · phoenix · CWE-770 | Yüksek8,7 | — | %0,8 | 7 Tem 2026 |
30İzleyin | CVE-2022-42975İstismar yok | socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding.phoenixframework · phoenix · CWE-863 | Yüksek7,5 | — | %0,6 | 17 Eki 2022 |
25İzleyin | CVE-2017-1000163Kavram kanıtı | The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirphoenixframework · phoenix · CWE-601 | Orta6,1 | — | %2,4 | 17 Kas 2017 |
25İzleyin | CVE-2026-56812İstismar yok | Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiffphoenixframework · phoenix · CWE-754 | Orta6,3 | — | %0,8 | 7 Tem 2026 |
24İzleyin | CVE-2021-46871İstismar yok | tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.phoenixframework · phoenix html · CWE-79 | Orta6,1 | — | %0,4 | 10 Oca 2023 |
- CVE-2026-5681134İzleyin
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
YüksekCVSS 8,7İstismar yokEPSS %1phoenixframework · phoenix7 Tem 2026
- CVE-2022-4297530İzleyin
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding.
YüksekCVSS 7,5İstismar yokEPSS %1phoenixframework · phoenix17 Eki 2022
- CVE-2017-100016325İzleyin
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redir
OrtaCVSS 6,1Kavram kanıtıEPSS %2phoenixframework · phoenix17 Kas 2017
- CVE-2026-5681225İzleyin
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
OrtaCVSS 6,3İstismar yokEPSS %1phoenixframework · phoenix7 Tem 2026
- CVE-2021-4687124İzleyin
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
OrtaCVSS 6,1İstismar yokEPSS %0phoenixframework · phoenix html10 Oca 2023