Known Vulnerabilities for products from Pwndoc Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Pwndoc Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-45771 json | An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via... | 8.8 - HIGH | 2022-12-05 | 2022-12-06 |
| CVE-2022-44023 json | PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for... | 5.3 - MEDIUM | 2022-10-30 | 2022-12-12 |
| CVE-2022-44022 json | PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for aut... | 5.3 - MEDIUM | 2022-10-30 | 2022-11-01 |
| CVE-2021-31590 json | PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. With ... | 8.8 - HIGH | 2021-07-19 | 2022-07-12 |