Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Recommendation Algorithm HIGH 7.5
CVE-2023-29218

The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for m…

Fix: after 2023-03-31
Fix from $1,950 2023-04-03
Twitter Server MEDIUM 5.4
CVE-2020-35774EPSS 86%

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /…

Fix: 20.12.0+
Fix from $1,600 2020-12-29
Secure Headers MEDIUM 5.8
CVE-2020-5216

In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-suppli…

Fix: 3.9.0 / 5.2.0+
Fix from $1,600 2020-01-23
Secure Headers MEDIUM 5.8
CVE-2020-5217

In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-suppli…

Fix: 3.8.0 / 5.1.0+
Fix from $1,600 2020-01-23
Twitter Kit HIGH 7.4
CVE-2019-16263

The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must c…

Fix: after 3.4.2
Fix from $1,950 2019-10-07
Twitter Kit MEDIUM 5.4
CVE-2019-5431

This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verificati…

Fix: after 3.4.0
Fix from $1,600 2019-05-06
Twitter Kit MEDIUM 5.4
CVE-2017-0911

Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to…

Fix: after 3.2.1
Fix from $1,600 2018-02-09
Twitter MEDIUM 5.9
CVE-2016-10511

The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint…

No fix yet
Fix from $1,600 2017-09-18
Groupama Toujours La MEDIUM 5.4
CVE-2014-6838

The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allow…

Mitigation only
Fix from $1,600 2014-09-30