prasklatechnology kayıtları
prasklatechnology üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-259 Use of Hard-coded Password1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-532 Insertion of Sensitive Information into Log File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-25814İstismar yok | NoSQL Injection Risk via Unsanitized Query Parametersprasklatechnology · placipy · CWE-74 | Kritik9,3 | — | %0,6 | 9 Şub 2026 |
37İzleyin | CVE-2026-25753İstismar yok | PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)prasklatechnology · placipy · CWE-259 | Kritik9,3 | — | %0,5 | 6 Şub 2026 |
37İzleyin | CVE-2026-25875İstismar yok | PlaciPy Admin Privilege Escalation via Trusted JWT Claimsprasklatechnology · placipy · CWE-863 | Kritik9,3 | — | %0,5 | 9 Şub 2026 |
37İzleyin | CVE-2026-25812İstismar yok | PlaciPy is Missing CSRF Protection on State-Changing Endpointsprasklatechnology · placipy · CWE-352 | Kritik9,3 | — | %0,2 | 9 Şub 2026 |
34İzleyin | CVE-2026-25813İstismar yok | PlaciPy Exposes Sensitive Data via Application Logsprasklatechnology · placipy · CWE-532 | Yüksek8,7 | — | %0,4 | 9 Şub 2026 |
21İzleyin | CVE-2026-25809İstismar yok | PlaciPy Code Execution Allowed Without Assessment Active State Validationprasklatechnology · placipy · CWE-285 | Orta5,3 | — | %0,6 | 9 Şub 2026 |
21İzleyin | CVE-2026-25810İstismar yok | PlaciPy is Missing Object-Level Authorization in student.submission.routes.tsprasklatechnology · placipy · CWE-862 | Orta5,3 | — | %0,5 | 9 Şub 2026 |
21İzleyin | CVE-2026-25876İstismar yok | PlaciPy is Missing Authorization on Assessment Results Endpointprasklatechnology · placipy · CWE-862 | Orta5,3 | — | %0,5 | 9 Şub 2026 |
21İzleyin | CVE-2026-25806İstismar yok | PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)prasklatechnology · placipy · CWE-862 | Orta5,3 | — | %0,4 | 9 Şub 2026 |
21İzleyin | CVE-2026-25811İstismar yok | PlaciPy Email Domain Trust Enables Cross-Tenant Data Access (Multi-Tenant Isolation Failure)prasklatechnology · placipy · CWE-863 | Orta5,3 | — | %0,4 | 9 Şub 2026 |
- CVE-2026-2581437İzleyin
NoSQL Injection Risk via Unsanitized Query Parameters
KritikCVSS 9,3İstismar yokEPSS %1prasklatechnology · placipy9 Şub 2026
- CVE-2026-2575337İzleyin
PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)
KritikCVSS 9,3İstismar yokEPSS %1prasklatechnology · placipy6 Şub 2026
- CVE-2026-2587537İzleyin
PlaciPy Admin Privilege Escalation via Trusted JWT Claims
KritikCVSS 9,3İstismar yokEPSS %1prasklatechnology · placipy9 Şub 2026
- CVE-2026-2581237İzleyin
PlaciPy is Missing CSRF Protection on State-Changing Endpoints
KritikCVSS 9,3İstismar yokEPSS %0prasklatechnology · placipy9 Şub 2026
- CVE-2026-2581334İzleyin
PlaciPy Exposes Sensitive Data via Application Logs
YüksekCVSS 8,7İstismar yokEPSS %0prasklatechnology · placipy9 Şub 2026
- CVE-2026-2580921İzleyin
PlaciPy Code Execution Allowed Without Assessment Active State Validation
OrtaCVSS 5,3İstismar yokEPSS %1prasklatechnology · placipy9 Şub 2026
- CVE-2026-2581021İzleyin
PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts
OrtaCVSS 5,3İstismar yokEPSS %0prasklatechnology · placipy9 Şub 2026
- CVE-2026-2587621İzleyin
PlaciPy is Missing Authorization on Assessment Results Endpoint
OrtaCVSS 5,3İstismar yokEPSS %0prasklatechnology · placipy9 Şub 2026
- CVE-2026-2580621İzleyin
PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)
OrtaCVSS 5,3İstismar yokEPSS %0prasklatechnology · placipy9 Şub 2026
- CVE-2026-2581121İzleyin
PlaciPy Email Domain Trust Enables Cross-Tenant Data Access (Multi-Tenant Isolation Failure)
OrtaCVSS 5,3İstismar yokEPSS %0prasklatechnology · placipy9 Şub 2026