Anuko
9 CVEs tracked since 2020. Since Nov 2020, none of them reached CISA KEV.
Anuko CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-11 | 2 | 0 |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | 2 | 0 |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | 2 | 0 |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | 3 | 0 |
Products
The products that kept showing up in Anuko's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 13 most recently published vulnerabilities affecting Anuko.
- CVE-2023-32308SQL Injection Vulnerability in anuko timetracker8.2
- CVE-2023-32306Time Tracker has Blind SQL Injection Vulnerability in Reports8.8
- CVE-2023-32066Time Tracker has Stored XSS vulnerability in Week View plugin5.4
- CVE-2022-24707SQL injection in anuko timetracker7.4
- CVE-2022-24708Stored XSS vulnerability in anuko/timetracker6.5
- CVE-2021-43851SQL injection vulnerability in anuko timetracker8.1
- CVE-2021-41156Reflected XSS vulnerability6.8
- CVE-2021-41139Reflected XSS vulnerability in time.php8.1
- CVE-2021-29436Cross site request forgery vulnerability5.4
- CVE-2021-21352Predictable tokens used for password resets6.8
- CVE-2020-27422In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.9.8
- CVE-2020-27423Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox7.5
- CVE-2020-15255CSV injection in Anuko Time Tracker8.7
The record
- Peak rank
- #132 in Nov 2020
- Busiest month shown
- May 2023, 3 CVEs
- Months with a KEV entry
- 0 since Nov 2020
- Monthly snapshots
- 4 since 2020