pglombardo
- Products in analyzed data
- 1
- Catalog vulnerabilities
- 7
Severity across 7 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 7 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, pglombardo recorded 3 security vulnerabilities in the last 90 days across 1 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, PasswordPusher had the most security vulnerabilities in the pglombardo ecosystem, with 3 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-87816PasswordPusher before 2.11.1 Race Condition View Limit Bypass | Exploitation statusPublic exploit | FixYes | Affected productPasswordPusher | Published09/09/2026 | SeverityHigh |
CVE-2026-62382PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison | Exploitation statusPublic exploit | FixYes | Affected productPasswordPusher | Published08/22/2026 | SeverityMedium |
CVE-2026-61458PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint | Exploitation statusPublic exploit | FixYes | Affected productPasswordPusher | Published07/13/2026 | SeverityHigh |
CVE-2026-41308Password Pusher: JSON API `/p.json` file upload alias bypasses file-push authentication | Exploitation statusNot known exploited | FixYes | Affected productPasswordPusher | Published05/08/2026 | SeverityMedium |
CVE-2024-56733Password Pusher Allows Session Token Interception Leading to Potential Hijacking | Exploitation statusNot known exploited | FixNot confirmed | Affected productPasswordPusher | Published12/30/2024 | SeverityMedium |
CVE-2024-52796Password Pusher's rate limiter can be bypassed by forging proxy headers | Exploitation statusNot known exploited | FixNot confirmed | Affected productPasswordPusher | Published11/20/2024 | SeverityMedium |
CVE-2024-51989Cross-site Scripting (XSS) Vulnerability in PasswordPusher | Exploitation statusNot known exploited | FixNot confirmed | Affected productPasswordPusher | Published11/07/2024 | SeverityHigh |