VYPR

CWE-1125

Excessive Attack Surface

BaseIncomplete

Description

The product has an attack surface whose quantitative measurement exceeds a desirable maximum.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (5)

  • CVE-2024-5386HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining the password reset token. The vulnerability is triggered when…

  • CVE-2023-0435CriJan 22, 2023
    risk 0.57cvss 9.8epss 0.01

    Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.

  • CVE-2022-1715CriMay 13, 2022
    risk 0.57cvss 9.8epss 0.01

    Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

  • CVE-2023-49722HigJan 9, 2024
    risk 0.54cvss 8.3epss 0.00

    Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

  • CVE-2022-2037HigJun 9, 2022
    risk 0.00cvss 8.0epss 0.01

    Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.