thecodingmachine kayıtları
thecodingmachine üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %68,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-73 External Control of File Name or Path2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-1333 Inefficient Regular Expression Complexity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-13450İstismar yok | A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writabthecodingmachine · gotenberg · CWE-22 | Kritik9,8 | — | %5,6 | 7 Oca 2021 |
40Planlayın | CVE-2026-42589Kavram kanıtı | Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injectionthecodingmachine · gotenberg · CWE-78 | Kritik9,8 | — | %3,7 | 14 May 2026 |
40Planlayın | CVE-2020-13451İstismar yok | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice cothecodingmachine · gotenberg · CWE-459 | Kritik9,8 | — | %3,0 | 7 Oca 2021 |
40Planlayın | CVE-2020-13452İstismar yok | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, thecodingmachine · gotenberg · CWE-276 | Kritik9,8 | — | %2,7 | 7 Oca 2021 |
38İzleyin | CVE-2026-42596Kavram kanıtı | Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhookthecodingmachine · gotenberg · CWE-918 | Kritik9,4 | — | %1,8 | 14 May 2026 |
36İzleyin | CVE-2026-40281İstismar yok | Gotenberg vulnerable to argument injection via newlines in ExifTool metadata valuesthecodingmachine · gotenberg · CWE-88 | Kritik9,1 | — | %0,7 | 6 May 2026 |
34İzleyin | CVE-2026-35458İstismar yok | Gotenberg has a ReDoS via extraHttpHeaders scope featurethecodingmachine · gotenberg · CWE-1333 | Yüksek8,7 | — | %0,6 | 7 Nis 2026 |
34İzleyin | CVE-2026-42595İstismar yok | Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypassthecodingmachine · gotenberg · CWE-918 | Yüksek8,6 | — | %0,4 | 14 May 2026 |
32İzleyin | CVE-2026-40280Kavram kanıtı | Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-liststhecodingmachine · gotenberg · CWE-918 | Yüksek7,8 | — | %2,1 | 5 May 2026 |
32İzleyin | CVE-2026-40893İstismar yok | Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Movethecodingmachine · gotenberg · CWE-73 | Yüksek8,2 | — | %0,5 | 14 May 2026 |
32İzleyin | CVE-2026-42590İstismar yok | Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklistthecodingmachine · gotenberg · CWE-184 | Yüksek8,2 | — | %0,4 | 14 May 2026 |
32İzleyin | CVE-2026-42591İstismar yok | Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8thecodingmachine · gotenberg · CWE-918 | Yüksek8,2 | — | %0,3 | 14 May 2026 |
31İzleyin | CVE-2020-13449İstismar yok | A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.thecodingmachine · gotenberg · CWE-22 | Yüksek7,5 | — | %4,9 | 7 Oca 2021 |
31İzleyin | CVE-2020-14160İstismar yok | An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able tthecodingmachine · gotenberg · CWE-918 | Yüksek7,5 | — | %1,7 | 26 Ağu 2021 |
31İzleyin | CVE-2026-27018Kavram kanıtı | Gotenberg: Chromium deny-list bypass via case-insensitive URL schemethecodingmachine · gotenberg · CWE-22 | Yüksek7,8 | — | %1,6 | 30 Mar 2026 |
30İzleyin | CVE-2026-42594İstismar yok | Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutinethecodingmachine · gotenberg · CWE-362 | Yüksek7,5 | — | %0,4 | 14 May 2026 |
27İzleyin | CVE-2026-39383İstismar yok | Gotenberg unauthenticated blind SSRF via unfiltered webhook URLthecodingmachine · gotenberg · CWE-918 | Orta6,9 | — | %0,3 | 5 May 2026 |
24İzleyin | CVE-2020-14161İstismar yok | It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.thecodingmachine · gotenberg · CWE-79 | Orta6,1 | — | %0,9 | 26 Ağu 2021 |
23İzleyin | CVE-2026-42597İstismar yok | Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// schemethecodingmachine · gotenberg · CWE-73 | Orta5,9 | — | %0,4 | 14 May 2026 |
21İzleyin | CVE-2021-23345İstismar yok | Server-side Request Forgery (SSRF)thecodingmachine · gotenberg · CWE-918 | Orta5,3 | — | %1,1 | 26 Şub 2021 |
21İzleyin | CVE-2026-42593İstismar yok | Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routesthecodingmachine · gotenberg · CWE-22 | Orta5,3 | — | %0,4 | 14 May 2026 |
21İzleyin | CVE-2026-42592İstismar yok | Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routesthecodingmachine · gotenberg · CWE-367 | Orta5,3 | — | %0,2 | 14 May 2026 |
- CVE-2020-1345041Planlayın
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writab
KritikCVSS 9,8İstismar yokEPSS %6thecodingmachine · gotenberg7 Oca 2021
- CVE-2026-4258940Planlayın
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
KritikCVSS 9,8Kavram kanıtıEPSS %4thecodingmachine · gotenberg14 May 2026
- CVE-2020-1345140Planlayın
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co
KritikCVSS 9,8İstismar yokEPSS %3thecodingmachine · gotenberg7 Oca 2021
- CVE-2020-1345240Planlayın
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,
KritikCVSS 9,8İstismar yokEPSS %3thecodingmachine · gotenberg7 Oca 2021
- CVE-2026-4259638İzleyin
Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
KritikCVSS 9,4Kavram kanıtıEPSS %2thecodingmachine · gotenberg14 May 2026
- CVE-2026-4028136İzleyin
Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values
KritikCVSS 9,1İstismar yokEPSS %1thecodingmachine · gotenberg6 May 2026
- CVE-2026-3545834İzleyin
Gotenberg has a ReDoS via extraHttpHeaders scope feature
YüksekCVSS 8,7İstismar yokEPSS %1thecodingmachine · gotenberg7 Nis 2026
- CVE-2026-4259534İzleyin
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
YüksekCVSS 8,6İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026
- CVE-2026-4028032İzleyin
Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists
YüksekCVSS 7,8Kavram kanıtıEPSS %2thecodingmachine · gotenberg5 May 2026
- CVE-2026-4089332İzleyin
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
YüksekCVSS 8,2İstismar yokEPSS %1thecodingmachine · gotenberg14 May 2026
- CVE-2026-4259032İzleyin
Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist
YüksekCVSS 8,2İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026
- CVE-2026-4259132İzleyin
Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8
YüksekCVSS 8,2İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026
- CVE-2020-1344931İzleyin
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
YüksekCVSS 7,5İstismar yokEPSS %5thecodingmachine · gotenberg7 Oca 2021
- CVE-2020-1416031İzleyin
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able t
YüksekCVSS 7,5İstismar yokEPSS %2thecodingmachine · gotenberg26 Ağu 2021
- CVE-2026-2701831İzleyin
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
YüksekCVSS 7,8Kavram kanıtıEPSS %2thecodingmachine · gotenberg30 Mar 2026
- CVE-2026-4259430İzleyin
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
YüksekCVSS 7,5İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026
- CVE-2026-3938327İzleyin
Gotenberg unauthenticated blind SSRF via unfiltered webhook URL
OrtaCVSS 6,9İstismar yokEPSS %0thecodingmachine · gotenberg5 May 2026
- CVE-2020-1416124İzleyin
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
OrtaCVSS 6,1İstismar yokEPSS %1thecodingmachine · gotenberg26 Ağu 2021
- CVE-2026-4259723İzleyin
Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
OrtaCVSS 5,9İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026
- CVE-2021-2334521İzleyin
Server-side Request Forgery (SSRF)
OrtaCVSS 5,3İstismar yokEPSS %1thecodingmachine · gotenberg26 Şub 2021
- CVE-2026-4259321İzleyin
Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
OrtaCVSS 5,3İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026
- CVE-2026-4259221İzleyin
Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
OrtaCVSS 5,3İstismar yokEPSS %0thecodingmachine · gotenberg14 May 2026