Vulnerabilidades em CISA

27 resultados
Análise Vexday

A CISA apresenta um perfil de risco baixo com 12 CVEs catalogadas, nenhuma atualmente sob exploração ativa e apenas 2 classificadas como críticas. A fraqueza dominante é buffer overflow (CWE-787), padrão em software legado, mas a vulnerabilidade mais recente data de mais de 90 dias, indicando risco estável e sem pressão imediata de remediação.

CVE-2023-7243CRITICALEthercat Zeek Plugin Out-of-bounds WriteEPSS 0.8%CVE-2023-7244CRITICALEthercat Zeek Plugin Out-of-bounds WriteEPSS 0.8%CVE-2025-35432MEDIUMCISA Thorium does not rate limit account verification email messagesEPSS 0.6%CVE-2025-35436MEDIUMCISA Thorium account verification email error handlingEPSS 0.6%CVE-2023-7242HIGHEthercat Zeek Plugin Out-of-bounds ReadEPSS 0.5%CVE-2025-35430MEDIUMCISA Thorium insecure downloaded file path validationEPSS 0.5%CVE-2025-35435MEDIUMCISA Thorium download stream divide by zeroEPSS 0.4%CVE-2026-43510MEDIUMCISA manage.get.gov insecure portfolio administrative privilegesEPSS 0.4%CVE-2026-90445HIGHAn interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extractedEPSS 0.3%CVE-2026-90451HIGHAn example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled EPSS 0.3%CVE-2026-90443MEDIUMA web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does noEPSS 0.3%CVE-2026-90449MEDIUMWhen a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface EPSS 0.3%CVE-2025-35431MEDIUMCISA Thorium LDAP injectionEPSS 0.3%CVE-2025-35433LOWCISA Thorium does not properly invalidate previously used tokensEPSS 0.3%CVE-2026-90447HIGHA routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-suppliEPSS 0.3%CVE-2026-90456CRITICALAn example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative pasEPSS 0.3%CVE-2026-90444HIGHA file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. AnEPSS 0.2%CVE-2026-90453MEDIUMA file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without EPSS 0.2%CVE-2026-90455MEDIUMA prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing thEPSS 0.2%CVE-2026-90450MEDIUMThe application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role reEPSS 0.2%