İçeriğe atla
Noroxi

Salesforce kayıtları

salesforce üreticisine ait 21 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%76,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

21 kayıt
  • CVE-2023-26136
    40Planlayın

    Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cooki

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    salesforce · tough-cookie1 Tem 2023

  • CVE-2021-1626
    40Planlayın

    MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both Cloud

    KritikCVSS 9,8İstismar yokEPSS %2

    salesforce · mule26 Mar 2021

  • CVE-2021-1628
    39İzleyin

    MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both C

    KritikCVSS 9,8İstismar yokEPSS %1

    salesforce · mule26 Mar 2021

  • CVE-2021-1627
    39İzleyin

    MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both

    KritikCVSS 9,8İstismar yokEPSS %1

    salesforce · mule26 Mar 2021

  • CVE-2026-22583
    39İzleyin

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (C

    KritikCVSS 9,8İstismar yokEPSS %1

    salesforce · marketing cloud engagement23 Oca 2026

  • CVE-2026-22582
    39İzleyin

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (M

    KritikCVSS 9,8İstismar yokEPSS %1

    salesforce · marketing cloud engagement23 Oca 2026

  • CVE-2016-15012
    39İzleyin

    forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    salesforce · mobile software development kit7 Oca 2023

  • CVE-2026-22586
    39İzleyin

    Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscr

    KritikCVSS 9,8İstismar yokEPSS %1

    salesforce · marketing cloud engagement23 Oca 2026

  • CVE-2026-22585
    39İzleyin

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr

    KritikCVSS 9,8İstismar yokEPSS %0

    salesforce · marketing cloud engagement23 Oca 2026

  • CVE-2026-22584
    39İzleyin

    Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Execut

    KritikCVSS 9,8İstismar yokEPSS %0

    salesforce · uni2ts9 Oca 2026

  • CVE-2024-39344
    32İzleyin

    An issue was discovered in the Docusign API package 8.142.14 for Salesforce.

    YüksekCVSS 8,1İstismar yokEPSS %1

    21 Ağu 2024

  • CVE-2017-15010
    31İzleyin

    A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.

    YüksekCVSS 7,5İstismar yokEPSS %3

    salesforce · tough-cookie3 Eki 2017

  • CVE-2021-1630
    30İzleyin

    XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime F

    YüksekCVSS 7,5İstismar yokEPSS %1

    salesforce · mule5 Ağu 2021

  • CVE-2025-64320
    26İzleyin

    Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This is

    OrtaCVSS 6,5İstismar yokEPSS %0

    salesforce · agentforce vibes4 Kas 2025

  • CVE-2025-10875
    26İzleyin

    Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.Thi

    OrtaCVSS 6,5İstismar yokEPSS %0

    salesforce · mulesoft anypoint code builder4 Kas 2025

  • NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result

    OrtaCVSS 5,3İstismar yokEPSS %2

    salesforce · tough-cookie5 Eyl 2018

  • CVE-2025-64318
    21İzleyin

    Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Write

    OrtaCVSS 5,3İstismar yokEPSS %0

    salesforce · mulesoft anypoint code builder4 Kas 2025

  • CVE-2025-64321
    21İzleyin

    Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable

    OrtaCVSS 5,3İstismar yokEPSS %0

    salesforce · agentforce vibes4 Kas 2025

  • CVE-2025-64322
    21İzleyin

    Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable C

    OrtaCVSS 5,3İstismar yokEPSS %0

    salesforce · agentforce vibes4 Kas 2025

  • CVE-2025-64319
    21İzleyin

    Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeab

    OrtaCVSS 5,3İstismar yokEPSS %0

    salesforce · mulesoft anypoint code builder4 Kas 2025

  • CVE-2026-34951
    20İzleyin

    Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessions

    OrtaCVSS 5,1İstismar yokEPSS %0

    salesforce · workbench6 Nis 2026