Vulnerabilidades en ransomlook
14 resultadosAnálisis Vexday
A Ransomlook apresenta 13 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e potencialmente ainda não mitigada. Embora 4 sejam classificadas como críticas, nenhuma está sob exploração ativa conhecida (KEV), sugerindo janela de oportunidade para remediação. A fraqueza dominante é controle de acesso inadequado (CWE-862), típica de problemas de autorização que demandam revisão arquitetural.
CVE-2026-78369HIGHMissing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLookEPSS 0.5%CVE-2026-78370CRITICALRansomLook Unauthenticated Database Export Exposes Private DataEPSS 0.5%CVE-2026-78386HIGHUnauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook APIEPSS 0.5%CVE-2026-78372CRITICALRansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note DataEPSS 0.5%CVE-2026-78551HIGHRansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication AttemptsEPSS 0.4%CVE-2026-78381HIGHRansomLook Arbitrary File Read via Path Traversal in Post screen FieldEPSS 0.4%CVE-2026-78555CRITICALRansomLook API Key Disclosure Through /admin/apikeys HTML SourceEPSS 0.4%CVE-2026-78387CRITICALRansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration ModificationEPSS 0.4%CVE-2026-78380HIGHPrivate Group and Market Posts Disclosed Through Public Notification Channels in RansomLookEPSS 0.3%CVE-2026-78378MEDIUMRedis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook DataEPSS 0.3%CVE-2026-40584MEDIUMRansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information ExposureEPSS 0.3%CVE-2026-78391HIGHStored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLookEPSS 0.3%CVE-2026-78385HIGHRansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File AccessEPSS 0.3%CVE-2026-78553HIGHInsecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in RansomLookEPSS 0.1%