Salesforce kayıtları
salesforce üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %76,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-26136Kavram kanıtı | Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cookisalesforce · tough-cookie · CWE-1321 | Kritik9,8 | — | %2,5 | 1 Tem 2023 |
40Planlayın | CVE-2021-1626İstismar yok | MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both Cloudsalesforce · mule | Kritik9,8 | — | %2,0 | 26 Mar 2021 |
39İzleyin | CVE-2021-1628İstismar yok | MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both Csalesforce · mule · CWE-611 | Kritik9,8 | — | %1,2 | 26 Mar 2021 |
39İzleyin | CVE-2021-1627İstismar yok | MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect bothsalesforce · mule · CWE-918 | Kritik9,8 | — | %1,0 | 26 Mar 2021 |
39İzleyin | CVE-2026-22583İstismar yok | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (Csalesforce · marketing cloud engagement · CWE-88 | Kritik9,8 | — | %0,7 | 23 Oca 2026 |
39İzleyin | CVE-2026-22582İstismar yok | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (Msalesforce · marketing cloud engagement · CWE-88 | Kritik9,8 | — | %0,7 | 23 Oca 2026 |
39İzleyin | CVE-2016-15012İstismar yok | forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injectionsalesforce · mobile software development kit · CWE-89 | Kritik9,8 | — | %0,7 | 7 Oca 2023 |
39İzleyin | CVE-2026-22586İstismar yok | Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscrsalesforce · marketing cloud engagement · CWE-321 | Kritik9,8 | — | %0,6 | 23 Oca 2026 |
39İzleyin | CVE-2026-22585İstismar yok | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Prsalesforce · marketing cloud engagement · CWE-327 | Kritik9,8 | — | %0,4 | 23 Oca 2026 |
39İzleyin | CVE-2026-22584İstismar yok | Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executsalesforce · uni2ts · CWE-94 | Kritik9,8 | — | %0,4 | 9 Oca 2026 |
32İzleyin | CVE-2024-39344İstismar yok | An issue was discovered in the Docusign API package 8.142.14 for Salesforce.CWE-200 | Yüksek8,1 | — | %0,5 | 21 Ağu 2024 |
31İzleyin | CVE-2017-15010İstismar yok | A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.salesforce · tough-cookie · CWE-400 | Yüksek7,5 | — | %3,3 | 3 Eki 2017 |
30İzleyin | CVE-2021-1630İstismar yok | XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fsalesforce · mule · CWE-611 | Yüksek7,5 | — | %1,1 | 5 Ağu 2021 |
26İzleyin | CVE-2025-64320İstismar yok | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issalesforce · agentforce vibes · CWE-94 | Orta6,5 | — | %0,2 | 4 Kas 2025 |
26İzleyin | CVE-2025-10875İstismar yok | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.Thisalesforce · mulesoft anypoint code builder · CWE-94 | Orta6,5 | — | %0,2 | 4 Kas 2025 |
22İzleyin | CVE-2016-1000232İstismar yok | NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result salesforce · tough-cookie · CWE-20 | Orta5,3 | — | %2,4 | 5 Eyl 2018 |
21İzleyin | CVE-2025-64318İstismar yok | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writesalesforce · mulesoft anypoint code builder · CWE-94 | Orta5,3 | — | %0,2 | 4 Kas 2025 |
21İzleyin | CVE-2025-64321İstismar yok | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeablesalesforce · agentforce vibes · CWE-94 | Orta5,3 | — | %0,2 | 4 Kas 2025 |
21İzleyin | CVE-2025-64322İstismar yok | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Csalesforce · agentforce vibes · CWE-732 | Orta5,3 | — | %0,2 | 4 Kas 2025 |
21İzleyin | CVE-2025-64319İstismar yok | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeabsalesforce · mulesoft anypoint code builder · CWE-732 | Orta5,3 | — | %0,2 | 4 Kas 2025 |
20İzleyin | CVE-2026-34951İstismar yok | Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessionssalesforce · workbench · CWE-79 | Orta5,1 | — | %0,3 | 6 Nis 2026 |
- CVE-2023-2613640Planlayın
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cooki
KritikCVSS 9,8Kavram kanıtıEPSS %3salesforce · tough-cookie1 Tem 2023
- CVE-2021-162640Planlayın
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both Cloud
KritikCVSS 9,8İstismar yokEPSS %2salesforce · mule26 Mar 2021
- CVE-2021-162839İzleyin
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both C
KritikCVSS 9,8İstismar yokEPSS %1salesforce · mule26 Mar 2021
- CVE-2021-162739İzleyin
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both
KritikCVSS 9,8İstismar yokEPSS %1salesforce · mule26 Mar 2021
- CVE-2026-2258339İzleyin
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (C
KritikCVSS 9,8İstismar yokEPSS %1salesforce · marketing cloud engagement23 Oca 2026
- CVE-2026-2258239İzleyin
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (M
KritikCVSS 9,8İstismar yokEPSS %1salesforce · marketing cloud engagement23 Oca 2026
- CVE-2016-1501239İzleyin
forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injection
KritikCVSS 9,8İstismar yokEPSS %1salesforce · mobile software development kit7 Oca 2023
- CVE-2026-2258639İzleyin
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscr
KritikCVSS 9,8İstismar yokEPSS %1salesforce · marketing cloud engagement23 Oca 2026
- CVE-2026-2258539İzleyin
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr
KritikCVSS 9,8İstismar yokEPSS %0salesforce · marketing cloud engagement23 Oca 2026
- CVE-2026-2258439İzleyin
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Execut
KritikCVSS 9,8İstismar yokEPSS %0salesforce · uni2ts9 Oca 2026
- CVE-2024-3934432İzleyin
An issue was discovered in the Docusign API package 8.142.14 for Salesforce.
YüksekCVSS 8,1İstismar yokEPSS %121 Ağu 2024
- CVE-2017-1501031İzleyin
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.
YüksekCVSS 7,5İstismar yokEPSS %3salesforce · tough-cookie3 Eki 2017
- CVE-2021-163030İzleyin
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime F
YüksekCVSS 7,5İstismar yokEPSS %1salesforce · mule5 Ağu 2021
- CVE-2025-6432026İzleyin
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This is
OrtaCVSS 6,5İstismar yokEPSS %0salesforce · agentforce vibes4 Kas 2025
- CVE-2025-1087526İzleyin
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.Thi
OrtaCVSS 6,5İstismar yokEPSS %0salesforce · mulesoft anypoint code builder4 Kas 2025
- CVE-2016-100023222İzleyin
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result
OrtaCVSS 5,3İstismar yokEPSS %2salesforce · tough-cookie5 Eyl 2018
- CVE-2025-6431821İzleyin
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Write
OrtaCVSS 5,3İstismar yokEPSS %0salesforce · mulesoft anypoint code builder4 Kas 2025
- CVE-2025-6432121İzleyin
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable
OrtaCVSS 5,3İstismar yokEPSS %0salesforce · agentforce vibes4 Kas 2025
- CVE-2025-6432221İzleyin
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable C
OrtaCVSS 5,3İstismar yokEPSS %0salesforce · agentforce vibes4 Kas 2025
- CVE-2025-6431921İzleyin
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeab
OrtaCVSS 5,3İstismar yokEPSS %0salesforce · mulesoft anypoint code builder4 Kas 2025
- CVE-2026-3495120İzleyin
Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessions
OrtaCVSS 5,1İstismar yokEPSS %0salesforce · workbench6 Nis 2026