yf-exam_project CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

yf-exam_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all yf-exam_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk sql injection, with potential vendor impact data exposure across vendor surface software deployment and vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-26779 CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE). [email protected] 9.8 2.02% 2023-03-03 2025-03-06
CVE-2023-25403 CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication. [email protected] 7.5 0.17% 2023-03-03 2025-03-07
CVE-2023-25402 CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload. [email protected] 7.5 0.19% 2023-03-03 2025-03-06
CVE-2023-26780 CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection. [email protected] 9.8 0.23% 2023-03-02 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence