Securly kayıtları
securly üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-798 Use of Hard-coded Credentials1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-916 Use of Password Hash With Insufficient Computational Effort1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2026-8888Kavram kanıtı | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular exsecurly · securly · CWE-917 | Yüksek7,5 | — | %0,6 | 3 Haz 2026 |
30İzleyin | CVE-2026-8879İstismar yok | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContensecurly · securly · CWE-829 | Yüksek7,5 | — | %0,5 | 3 Haz 2026 |
30İzleyin | CVE-2026-8889İstismar yok | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matsecurly · securly · CWE-407 | Yüksek7,5 | — | %0,3 | 3 Haz 2026 |
30İzleyin | CVE-2026-8878İstismar yok | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive securly · securly · CWE-326 | Yüksek7,5 | — | %0,3 | 3 Haz 2026 |
30İzleyin | CVE-2026-8881İstismar yok | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption.securly · securly · CWE-916 | Yüksek7,5 | — | %0,2 | 3 Haz 2026 |
29İzleyin | CVE-2026-8876İstismar yok | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js.securly · securly · CWE-798 | Yüksek7,3 | — | %0,3 | 3 Haz 2026 |
28İzleyin | CVE-2026-8874İstismar yok | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTsecurly · securly · CWE-319 | Yüksek7,1 | — | %0,2 | 3 Haz 2026 |
- CVE-2026-888830İzleyin
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular ex
YüksekCVSS 7,5Kavram kanıtıEPSS %1securly · securly3 Haz 2026
- CVE-2026-887930İzleyin
Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerConten
YüksekCVSS 7,5İstismar yokEPSS %1securly · securly3 Haz 2026
- CVE-2026-888930İzleyin
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist mat
YüksekCVSS 7,5İstismar yokEPSS %0securly · securly3 Haz 2026
- CVE-2026-887830İzleyin
Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive
YüksekCVSS 7,5İstismar yokEPSS %0securly · securly3 Haz 2026
- CVE-2026-888130İzleyin
Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption.
YüksekCVSS 7,5İstismar yokEPSS %0securly · securly3 Haz 2026
- CVE-2026-887629İzleyin
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js.
YüksekCVSS 7,3İstismar yokEPSS %0securly · securly3 Haz 2026
- CVE-2026-887428İzleyin
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTT
YüksekCVSS 7,1İstismar yokEPSS %0securly · securly3 Haz 2026