Products: 3
    Vulnerabilities: 2
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-54599

    The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue is SSO misconfiguration.

    Last Modified: Sep 10, 2025
    Published: Sep 02, 2025

    CVE-2025-54598

    The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.

    Last Modified: Sep 09, 2025
    Published: Aug 27, 2025
    Items Per Page
    Bevy Vulnerabilities & Security CVEs | CVE-DB