Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
tyk tyk vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-42283
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows malicious user to access and dump the database via a crafted SQL query.
Tyk Tyk 5.0.3
1 Github repository
9.8
CVSSv3
CVE-2023-42284
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows malicious user to access and dump the database via a crafted SQL query.
Tyk Tyk 5.0.3
1 Github repository
9.1
CVSSv3
CVE-2021-23365
The package github.com/tyktechnologies/tyk-identity-broker prior to 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/dec...
Tyk Tyk-identity-broker
5.3
CVSSv3
CVE-2021-23357
All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function. This function is able to delete arbitrary JSON files on the disk where Tyk is running via the management API. The APIID is provided by the u...
Tyk Tyk
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started