Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-27978
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
Tooljet
No fix yet
MEDIUM 5.4
CVE-2022-27979
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…
Tooljet
No fix yet
MEDIUM 6.5
CVE-2022-4111
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.
Tooljet
1.27.0+
HIGH 7.5
CVE-2022-3422
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the fo…
Tooljet
1.26.1+
HIGH 8.8
CVE-2022-3019
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comme…
Tooljet
1.23.0+
HIGH 8.8
CVE-2022-2631
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
Tooljet
1.19.0+
HIGH 8.0
CVE-2022-2037
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
Tooljet
1.16.0+
HIGH 8.8
CVE-2022-23067
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite li…
Tooljet
after 1.2.2
MEDIUM 5.4
CVE-2022-23068
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name f…
Tooljet
after 1.10.2