CWE-1125
5 CVEs • Abstraction: Base
Excessive Attack Surface
The product has an attack surface whose quantitative measurement exceeds a desirable maximum.
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining th...Show more |
1Bosch 3Bcc101 Firmware Bcc102 FirmwareBcc50 FirmwareJun 17, 2026 Jan 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network. |
Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41. |
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. |
1Facturascripts 1Facturascripts Jun 17, 2026 May 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07. |