İçeriğe atla
Noroxi

thecodingmachine kayıtları

thecodingmachine üreticisine ait 22 yayımlanmış kayıt.

Tüm kayıtlar

22 kayıt
  • CVE-2020-13450
    41Planlayın

    A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writab

    KritikCVSS 9,8İstismar yokEPSS %6

    thecodingmachine · gotenberg7 Oca 2021

  • CVE-2026-42589
    40Planlayın

    Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    thecodingmachine · gotenberg14 May 2026

  • CVE-2020-13451
    40Planlayın

    An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co

    KritikCVSS 9,8İstismar yokEPSS %3

    thecodingmachine · gotenberg7 Oca 2021

  • CVE-2020-13452
    40Planlayın

    In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,

    KritikCVSS 9,8İstismar yokEPSS %3

    thecodingmachine · gotenberg7 Oca 2021

  • CVE-2026-42596
    38İzleyin

    Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook

    KritikCVSS 9,4Kavram kanıtıEPSS %2

    thecodingmachine · gotenberg14 May 2026

  • CVE-2026-40281
    36İzleyin

    Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values

    KritikCVSS 9,1İstismar yokEPSS %1

    thecodingmachine · gotenberg6 May 2026

  • CVE-2026-35458
    34İzleyin

    Gotenberg has a ReDoS via extraHttpHeaders scope feature

    YüksekCVSS 8,7İstismar yokEPSS %1

    thecodingmachine · gotenberg7 Nis 2026

  • CVE-2026-42595
    34İzleyin

    Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

    YüksekCVSS 8,6İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026

  • CVE-2026-40280
    32İzleyin

    Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists

    YüksekCVSS 7,8Kavram kanıtıEPSS %2

    thecodingmachine · gotenberg5 May 2026

  • CVE-2026-40893
    32İzleyin

    Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move

    YüksekCVSS 8,2İstismar yokEPSS %1

    thecodingmachine · gotenberg14 May 2026

  • CVE-2026-42590
    32İzleyin

    Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist

    YüksekCVSS 8,2İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026

  • CVE-2026-42591
    32İzleyin

    Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8

    YüksekCVSS 8,2İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026

  • CVE-2020-13449
    31İzleyin

    A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

    YüksekCVSS 7,5İstismar yokEPSS %5

    thecodingmachine · gotenberg7 Oca 2021

  • CVE-2020-14160
    31İzleyin

    An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able t

    YüksekCVSS 7,5İstismar yokEPSS %2

    thecodingmachine · gotenberg26 Ağu 2021

  • CVE-2026-27018
    31İzleyin

    Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme

    YüksekCVSS 7,8Kavram kanıtıEPSS %2

    thecodingmachine · gotenberg30 Mar 2026

  • CVE-2026-42594
    30İzleyin

    Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine

    YüksekCVSS 7,5İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026

  • CVE-2026-39383
    27İzleyin

    Gotenberg unauthenticated blind SSRF via unfiltered webhook URL

    OrtaCVSS 6,9İstismar yokEPSS %0

    thecodingmachine · gotenberg5 May 2026

  • CVE-2020-14161
    24İzleyin

    It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.

    OrtaCVSS 6,1İstismar yokEPSS %1

    thecodingmachine · gotenberg26 Ağu 2021

  • CVE-2026-42597
    23İzleyin

    Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme

    OrtaCVSS 5,9İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026

  • CVE-2021-23345
    21İzleyin

    Server-side Request Forgery (SSRF)

    OrtaCVSS 5,3İstismar yokEPSS %1

    thecodingmachine · gotenberg26 Şub 2021

  • CVE-2026-42593
    21İzleyin

    Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes

    OrtaCVSS 5,3İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026

  • CVE-2026-42592
    21İzleyin

    Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

    OrtaCVSS 5,3İstismar yokEPSS %0

    thecodingmachine · gotenberg14 May 2026