webtechnologies kayıtları
webtechnologies üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-863 Incorrect Authorization2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-73 External Control of File Name or Path1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-184 Incomplete List of Disallowed Inputs1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-35490İstismar yok | changedetection.io has an Authentication Bypass via Decorator Orderingwebtechnologies · changedetection · CWE-863 | Kritik9,8 | — | %0,6 | 7 Nis 2026 |
35İzleyin | CVE-2026-29065İstismar yok | changedetection.io: Zip Slip vulnerability in the backup restore functionalitywebtechnologies · changedetection · CWE-22 | Yüksek8,8 | — | %0,6 | 6 Mar 2026 |
35İzleyin | CVE-2026-29039İstismar yok | changedetection.io: XPath - Arbitrary File Read via unparsed-text()webtechnologies · changedetection · CWE-94 | Yüksek8,8 | — | %0,5 | 6 Mar 2026 |
34İzleyin | CVE-2026-27696İstismar yok | changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLswebtechnologies · changedetection · CWE-918 | Yüksek8,6 | — | %0,5 | 25 Şub 2026 |
33İzleyin | CVE-2026-33981İstismar yok | Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filterswebtechnologies · changedetection · CWE-200 | Yüksek8,3 | — | %0,5 | 27 Mar 2026 |
32İzleyin | CVE-2026-41895İstismar yok | changedetection.io: XXE vulnerability in the changedetection.io projectwebtechnologies · changedetection · CWE-611 | Yüksek8,2 | — | %0,4 | 12 May 2026 |
30İzleyin | CVE-2026-43891İstismar yok | changedetection.io: Arbitrary Local File Read via crafted backup restorewebtechnologies · changedetection · CWE-73 | Yüksek7,5 | — | %0,5 | 12 May 2026 |
28İzleyin | CVE-2026-35000İstismar yok | ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Readwebtechnologies · changedetection · CWE-184 | Yüksek7,1 | — | %0,5 | 1 Nis 2026 |
24İzleyin | CVE-2026-27645Kavram kanıtı | changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Responsewebtechnologies · changedetection · CWE-79 | Orta6,1 | — | %0,5 | 25 Şub 2026 |
24İzleyin | CVE-2026-29038İstismar yok | changedetection.io: Reflected XSS in RSS Tag Error Responsewebtechnologies · changedetection · CWE-79 | Orta6,1 | — | %0,3 | 6 Mar 2026 |
21İzleyin | CVE-2026-25527Kavram kanıtı | changedetection.io vulnerable to unauthenticated static path traversalwebtechnologies · changedetection · CWE-22 | Orta5,3 | — | %0,9 | 19 Şub 2026 |
21İzleyin | CVE-2023-24769İstismar yok | Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page.webtechnologies · changedetection · CWE-79 | Orta5,4 | — | %0,6 | 17 Şub 2023 |
14İzleyin | CVE-2024-23329İstismar yok | changedetection.io API endpoint is not secured with API tokenwebtechnologies · changedetection · CWE-863 | Düşük3,7 | — | %0,6 | 19 Oca 2024 |
- CVE-2026-3549039İzleyin
changedetection.io has an Authentication Bypass via Decorator Ordering
KritikCVSS 9,8İstismar yokEPSS %1webtechnologies · changedetection7 Nis 2026
- CVE-2026-2906535İzleyin
changedetection.io: Zip Slip vulnerability in the backup restore functionality
YüksekCVSS 8,8İstismar yokEPSS %1webtechnologies · changedetection6 Mar 2026
- CVE-2026-2903935İzleyin
changedetection.io: XPath - Arbitrary File Read via unparsed-text()
YüksekCVSS 8,8İstismar yokEPSS %1webtechnologies · changedetection6 Mar 2026
- CVE-2026-2769634İzleyin
changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs
YüksekCVSS 8,6İstismar yokEPSS %0webtechnologies · changedetection25 Şub 2026
- CVE-2026-3398133İzleyin
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
YüksekCVSS 8,3İstismar yokEPSS %0webtechnologies · changedetection27 Mar 2026
- CVE-2026-4189532İzleyin
changedetection.io: XXE vulnerability in the changedetection.io project
YüksekCVSS 8,2İstismar yokEPSS %0webtechnologies · changedetection12 May 2026
- CVE-2026-4389130İzleyin
changedetection.io: Arbitrary Local File Read via crafted backup restore
YüksekCVSS 7,5İstismar yokEPSS %0webtechnologies · changedetection12 May 2026
- CVE-2026-3500028İzleyin
ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read
YüksekCVSS 7,1İstismar yokEPSS %0webtechnologies · changedetection1 Nis 2026
- CVE-2026-2764524İzleyin
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
OrtaCVSS 6,1Kavram kanıtıEPSS %0webtechnologies · changedetection25 Şub 2026
- CVE-2026-2903824İzleyin
changedetection.io: Reflected XSS in RSS Tag Error Response
OrtaCVSS 6,1İstismar yokEPSS %0webtechnologies · changedetection6 Mar 2026
- CVE-2026-2552721İzleyin
changedetection.io vulnerable to unauthenticated static path traversal
OrtaCVSS 5,3Kavram kanıtıEPSS %1webtechnologies · changedetection19 Şub 2026
- CVE-2023-2476921İzleyin
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page.
OrtaCVSS 5,4İstismar yokEPSS %1webtechnologies · changedetection17 Şub 2023
- CVE-2024-2332914İzleyin
changedetection.io API endpoint is not secured with API token
DüşükCVSS 3,7İstismar yokEPSS %1webtechnologies · changedetection19 Oca 2024