Vulnerabilidades em HackerOne

470 resultados
Análise Vexday

Com 470 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o perfil de risco ativo do HackerOne situa-se abaixo da média geral do catálogo, sem registros de exploração confirmada no momento. A ausência de vulnerabilidades críticas e de novos registros nos últimos 90 dias sugere estabilidade recente no volume de descobertas, embora a existência de uma PoC pública mereça atenção por ampliar a superfície de exploração potencial. O CWE-311 — relacionado à ausência ou proteção inadequada de dados sensíveis em trânsito ou armazenamento — representa o tipo de falha mais recorrente, indicando uma área técnica que justifica revisão continuada de controles criptográficos. A CVE mais relevante no momento, CVE-2017-0901, apresenta EPSS de 0,2944, sinalizando probabilidade não desprezível de exploração e recomendando priorização no processo de remediação, mesmo sem confirmação de exploração ativa catalogada.

CVE-2017-16150wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker access to the filesystEPSS 2.0%CVE-2017-16168wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.EPSS 2.0%CVE-2017-16218dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem bEPSS 2.0%CVE-2017-16120liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placEPSS 2.0%CVE-2017-16142infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plEPSS 2.0%CVE-2017-16219yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing EPSS 2.0%CVE-2017-16148serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placinEPSS 2.0%CVE-2017-16220wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing EPSS 2.0%CVE-2017-16169looppake is a simple http server. looppake is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placEPSS 2.0%CVE-2017-16223nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plEPSS 2.0%CVE-2017-16036`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giEPSS 2.0%CVE-2017-16092Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to EPSS 2.0%CVE-2017-16105serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plEPSS 2.0%CVE-2017-16201zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plEPSS 2.0%CVE-2017-16094iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem EPSS 2.0%CVE-2017-16124node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker aEPSS 2.0%CVE-2017-16215sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placEPSS 2.0%CVE-2017-16157censorify.tanisjr is a simple web server and API RESTful service. censorify.tanisjr is vulnerable to a directory traversal issue, giving an EPSS 2.0%CVE-2017-16209enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placiEPSS 2.0%CVE-2017-16200uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by EPSS 2.0%