Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
tyk tyk vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-42283
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows malicious user to access and dump the database via a crafted SQL query.
Tyk Tyk 5.0.3
1 Github repository
9.8
CVSSv3
CVE-2023-42284
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows malicious user to access and dump the database via a crafted SQL query.
Tyk Tyk 5.0.3
1 Github repository
9.1
CVSSv3
CVE-2021-23365
The package github.com/tyktechnologies/tyk-identity-broker prior to 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/dec...
5.3
CVSSv3
CVE-2021-23357
All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function. This function is able to delete arbitrary JSON files on the disk where Tyk is running via the management API. The APIID is provided by the u...
Tyk Tyk
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started