Vulnerabilidades em HackerOne

470 resultados
Análise Vexday

Com 470 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o perfil de risco ativo do HackerOne situa-se abaixo da média geral do catálogo, sem registros de exploração confirmada no momento. A ausência de vulnerabilidades críticas e de novos registros nos últimos 90 dias sugere estabilidade recente no volume de descobertas, embora a existência de uma PoC pública mereça atenção por ampliar a superfície de exploração potencial. O CWE-311 — relacionado à ausência ou proteção inadequada de dados sensíveis em trânsito ou armazenamento — representa o tipo de falha mais recorrente, indicando uma área técnica que justifica revisão continuada de controles criptográficos. A CVE mais relevante no momento, CVE-2017-0901, apresenta EPSS de 0,2944, sinalizando probabilidade não desprezível de exploração e recomendando priorização no processo de remediação, mesmo sem confirmação de exploração ativa catalogada.

CVE-2016-10678serc.js is a Selenium RC process wrapper serc.js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may beEPSS 1.7%CVE-2016-10602haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible tEPSS 1.7%CVE-2016-10691windows-seleniumjar is a module that downloads the Selenium Jar file windows-seleniumjar downloads binary resources over HTTP, which leaves EPSS 1.7%CVE-2016-10656qbs is a build tool that helps simplify the build process for developing projects across multiple platforms. qbs downloads binary resources EPSS 1.7%CVE-2016-10625headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads bEPSS 1.7%CVE-2016-10662tomita is a node wrapper for Yandex Tomita Parser tomita downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. IEPSS 1.7%CVE-2016-10580nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It EPSS 1.7%CVE-2016-10614httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may EPSS 1.7%CVE-2016-10615curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaEPSS 1.7%CVE-2016-10635broccoli-closure is a Closure compiler plugin for Broccoli. broccoli-closure before 1.3.1 downloads binary resources over HTTP, which leavesEPSS 1.7%CVE-2016-10682massif is a Phantomjs fork massif downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remEPSS 1.7%CVE-2016-10696windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTPEPSS 1.7%CVE-2016-10685pk-app-wonderbox is an integration with wonderbox pk-app-wonderbox downloads binary resources over HTTP, which leaves it vulnerable to MITM EPSS 1.7%CVE-2016-10601webdrvr is a npm wrapper for Selenium Webdriver including Chromedriver / IEDriver / IOSDriver / Ghostdriver. webdrvr downloads binary resourEPSS 1.7%CVE-2016-10671mystem-wrapper is a Yandex mystem app wrapper module. mystem-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITEPSS 1.7%CVE-2016-10660fis-parser-sass-bin a plugin for fis to compile sass using node-sass-binaries. fis-parser-sass-bin downloads binary resources over HTTP, whiEPSS 1.7%CVE-2016-10620atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which lEPSS 1.7%CVE-2016-10567product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information aboutEPSS 1.7%CVE-2016-10666tomita-parser is a Node wrapper for Yandex Tomita Parser tomita-parser downloads binary resources over HTTP, which leaves it vulnerable to MEPSS 1.7%CVE-2016-10566install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over EPSS 1.7%