Adrián Chaves
6 exploits
Active since Oct 2021
scrapy-splash < 0.8.0 - Credential Exposure via HttpAuthMiddleware
CVSS 7.4
scrapy < 2.6.1 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
scrapy < 2.11.1 - Denial of Service via XMLFeedSpider XML Parsing
CVSS 6.5
Scrapy < 1.8.4 and 2.0-2.11.1 - Authorization Header Exposure via Same-Domain Scheme Redirect
CVSS 7.5
Scrapy 2.0.0-2.11.1 - XML External Entity Injection via lxml Parsing
CVSS 7.5
scrapy < 2.11.1 - Authorization Header Leak via Cross-Domain Redirect
CVSS 7.5