stanford kayıtları
stanford üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-611 Improper Restriction of XML External Entity Reference4
- CWE-255 Credentials Management Errors1
- CWE-502 Deserialization of Untrusted Data1
- CWE-522 Insufficiently Protected Credentials1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-3878İstismar yok | Improper Restriction of XML External Entity Reference in stanfordnlp/corenlpstanford · corenlp · CWE-611 | Kritik9,8 | — | %1,9 | 15 Eki 2021 |
39İzleyin | CVE-2021-44550İstismar yok | An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).stanford · corenlp · CWE-74 | Kritik9,8 | — | %1,3 | 24 Şub 2022 |
39İzleyin | CVE-2022-0239İstismar yok | Improper Restriction of XML External Entity Reference in stanfordnlp/corenlpstanford · corenlp · CWE-611 | Kritik9,8 | — | %1,2 | 17 Oca 2022 |
39İzleyin | CVE-2023-39020İstismar yok | stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2Pipedstanford · stanford parser · CWE-94 | Kritik9,8 | — | %1,0 | 28 Tem 2023 |
30İzleyin | CVE-2013-2106İstismar yok | webauth before 4.6.1 has authentication credential disclosurestanford · webauth · CWE-522 | Yüksek7,5 | — | %1,6 | 3 Ara 2019 |
30İzleyin | CVE-2021-3869İstismar yok | Improper Restriction of XML External Entity Reference in stanfordnlp/corenlpstanford · corenlp · CWE-611 | Yüksek7,5 | — | %1,4 | 19 Eki 2021 |
30İzleyin | CVE-2026-54499İstismar yok | Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loadersstanford · stanza · CWE-502 | Yüksek7,5 | — | %0,5 | 8 Tem 2026 |
28İzleyin | CVE-2022-0198İstismar yok | Improper Restriction of XML External Entity Reference in stanfordnlp/corenlpstanford · corenlp · CWE-611 | Yüksek7,1 | — | %0,7 | 13 Oca 2022 |
17İzleyin | CVE-2009-2945İstismar yok | weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certastanford · webauth · CWE-255 | Orta4,3 | — | %0,9 | 15 Eyl 2009 |
- CVE-2021-387840Planlayın
Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp
KritikCVSS 9,8İstismar yokEPSS %2stanford · corenlp15 Eki 2021
- CVE-2021-4455039İzleyin
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
KritikCVSS 9,8İstismar yokEPSS %1stanford · corenlp24 Şub 2022
- CVE-2022-023939İzleyin
Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp
KritikCVSS 9,8İstismar yokEPSS %1stanford · corenlp17 Oca 2022
- CVE-2023-3902039İzleyin
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2Piped
KritikCVSS 9,8İstismar yokEPSS %1stanford · stanford parser28 Tem 2023
- CVE-2013-210630İzleyin
webauth before 4.6.1 has authentication credential disclosure
YüksekCVSS 7,5İstismar yokEPSS %2stanford · webauth3 Ara 2019
- CVE-2021-386930İzleyin
Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp
YüksekCVSS 7,5İstismar yokEPSS %1stanford · corenlp19 Eki 2021
- CVE-2026-5449930İzleyin
Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
YüksekCVSS 7,5İstismar yokEPSS %1stanford · stanza8 Tem 2026
- CVE-2022-019828İzleyin
Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp
YüksekCVSS 7,1İstismar yokEPSS %1stanford · corenlp13 Oca 2022
- CVE-2009-294517İzleyin
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certa
OrtaCVSS 4,3İstismar yokEPSS %1stanford · webauth15 Eyl 2009