Vulnerabilidades em dani-garcia
19 resultadosAnálise Vexday
dani-garcia apresenta 18 vulnerabilidades conhecidas, com 10 divulgadas nos últimos 90 dias, indicando descobertas recentes contínuas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) nem classificada como crítica, reduzindo o risco imediato de exploração em massa. A fraqueza dominante é CWE-863 (controle de acesso incorreto), sugerindo problemas de autenticação ou autorização que demandam atenção em avaliações de segurança.
CVE-2025-24364HIGHvaultwarden allows RCE in the admin panelEPSS 1.0%CVE-2025-24365HIGHvaultwarden allows escalation of privilege via variable confusion in OrgHeaders traitEPSS 0.7%CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%CVE-2026-47164HIGHVaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP IdentityEPSS 0.4%CVE-2026-47160MEDIUMVaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP BypassEPSS 0.4%CVE-2026-26012MEDIUMvaultwarden has Full Cipher Enumeration Ignoring Organization Collection PermissionsEPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2026-27802HIGHVaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by ManagerEPSS 0.3%CVE-2026-43912HIGHVaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another OrganizationEPSS 0.3%CVE-2026-43914HIGHVaultwarden: Brute-force protection bypass vulnerabilityEPSS 0.3%CVE-2026-27803HIGHVaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager RoleEPSS 0.3%CVE-2026-43913HIGHVaultwarden: Unconfirmed Owner Can Purge Entire Organization VaultEPSS 0.3%CVE-2026-27801MEDIUMVaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit EnforcementEPSS 0.3%CVE-2026-47158HIGHVaultwarden: CSRF in SSO Authorization FlowEPSS 0.3%CVE-2026-43911MEDIUMVaultwarden: Refresh tokens not invalidated on security stamp rotationEPSS 0.2%CVE-2026-33420MEDIUMVaultwarden missing authorization check allows Manager-role users to enumerate all collectionsEPSS 0.2%CVE-2026-27898MEDIUMVaultwarden: Unauthorized Access via Partial Update API on Another User’s CipherEPSS 0.2%CVE-2026-31835MEDIUMVaultwarden WebAuthn credential metadata tampered before signature verificationEPSS 0.2%CVE-2026-95814HIGHVaultwarden through 1.37.3 Authorization Bypass via Missing Status CheckEPSS —