apple502j
6 exploits
Active since Oct 2020
Scratch Addons < 1.3.2 - DOM-based Cross-Site Scripting in More Links Addon
CVSS 7.6
scratchoauth2 < 2021-04-12 - Authorization Bypass via User-Controlled Key in SpecificApps REST API
CVSS 6.5
ScratchOAuth2 <a91879bd58fa83b09283c0708a1864cdf067c64a - Auth Bypass
CVSS 10.0
ScratchOAuth2 <commit 1603f04e44ef67dde6ccffe866d2dca16defb293 - XSS
CVSS 6.1
Scratch Wiki scratch-confirmaccount-v3 - CSRF
CVSS 6.5
scratch-svg-renderer < 0.2.0-prerelease.20201019174008 - Cross-Site Scripting via SVG Injection in loadString
CVSS 9.6