Vulnerabilidades em lin-snow

20 resultados
Análise Vexday

Lin-snow apresenta baixo volume de vulnerabilidades (3 CVEs catalogadas) e nenhuma sob exploração ativa ou com severidade crítica, indicando risco controlado no curto prazo. A fraqueza dominante identificada é CWE-918 (Server-Side Request Forgery), que pode permitir requisições não autorizadas em contextos específicos. Sem publicações recentes de vulnerabilidades, o panorama de risco permanece estável.

CVE-2026-35037HIGHEch0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadataEPSS 0.6%CVE-2026-33638MEDIUMEch0 authenticated user-list exposed data via public `/api/allusers` endpointEPSS 0.5%CVE-2026-79665HIGHEch0 before 4.5.1 Authorization Bypass via Session TokensEPSS 0.4%CVE-2026-35036HIGHEch0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview FeatureEPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2026-79658HIGHEch0 before 5.0.1 Denial of Service via Accept-LanguageEPSS 0.3%CVE-2026-79666HIGHEch0 before 4.4.3 Missing Authorization via dashboard log endpointsEPSS 0.3%CVE-2026-79668MEDIUMEch0 before 4.7.3 Unauthenticated Like Endpoint Metric InflationEPSS 0.3%CVE-2026-79661MEDIUMEch0 before 4.7.3 Unauthenticated fav_count ModificationEPSS 0.2%CVE-2026-79673HIGHEch0 before 4.4.3 Scope Bypass via profile:read TokenEPSS 0.2%CVE-2026-79671MEDIUMEch0 before 4.4.3 SSRF via DNS Resolution BypassEPSS 0.2%CVE-2026-79660MEDIUMEch0 before 4.7.3 Email Disclosure via Public APIEPSS 0.2%CVE-2026-79664CRITICALEch0 before 4.7.3 Access Token Revocation BypassEPSS 0.2%CVE-2026-79659HIGHEch0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfoEPSS 0.2%CVE-2026-79662HIGHEch0 before 4.7.3 OAuth Redirect URI Validation BypassEPSS 0.2%CVE-2026-79667HIGHEch0 before 4.4.3 Authentication Bypass via Scope EnforcementEPSS 0.2%CVE-2026-79672HIGHEch0 before 4.4.3 Authentication Bypass via Comment PanelEPSS 0.2%CVE-2026-79669MEDIUMEch0 before 4.4.3 Missing Authorization on System LogsEPSS 0.2%CVE-2026-79670MEDIUMEch0 before 4.4.3 Stored XSS via SVG UploadEPSS 0.1%CVE-2026-79663MEDIUMEch0 before 4.7.3 Stored XSS via RSS feed tag namesEPSS 0.1%