Owasp
Owasp Dependency-track: vulnerabilidades y CVE
Owasp Dependency-track tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-64758 | Media (4.8) | 0.22% | — | 17 nov 2025 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since… |
| CVE-2025-61776 | Media (4.7) | 0.28% | — | 7 oct 2025 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.13.5, Dependency-Track may send credentials meant for a private… |
| CVE-2025-27137 | Media (4.4) | 0.19% | — | 24 feb 2025 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize… |
| CVE-2024-54002 | Media (5.3) | 0.31% | — | 4 dic 2024 | Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username… |
| CVE-2022-39351 | Media (4.4) | 0.21% | — | 25 oct 2022 | Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.6.0, performing an API request using a valid API key with… |
| CVE-2019-1020007 | Media (5.4) | 0.65% | — | 29 jul 2019 | Dependency-Track before 3.5.1 allows XSS. |