adremsoft kayıtları
adremsoft üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-522 Insufficiently Protected Credentials1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-14482İstismar yok | AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-798 | Kritik9,8 | — | %1,8 | 16 Ara 2020 |
39İzleyin | CVE-2019-14480İstismar yok | AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication adremsoft · netcrunch · CWE-200 | Kritik9,8 | — | %1,1 | 16 Ara 2020 |
36İzleyin | CVE-2019-14479İstismar yok | AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution.adremsoft · netcrunch · CWE-78 | Yüksek8,8 | — | %4,2 | 16 Ara 2020 |
36İzleyin | CVE-2019-14483İstismar yok | AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure.adremsoft · netcrunch | Yüksek8,8 | — | %1,8 | 16 Ara 2020 |
26İzleyin | CVE-2019-14476İstismar yok | AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.adremsoft · netcrunch · CWE-918 | Orta6,5 | — | %0,8 | 16 Ara 2020 |
22İzleyin | CVE-2019-14477İstismar yok | AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passworadremsoft · netcrunch · CWE-522 | Orta5,5 | — | %0,3 | 16 Ara 2020 |
21İzleyin | CVE-2019-14478İstismar yok | AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-79 | Orta5,4 | — | %0,6 | 16 Ara 2020 |
21İzleyin | CVE-2019-14481İstismar yok | AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-352 | Orta5,4 | — | %0,4 | 16 Ara 2020 |
- CVE-2019-1448240Planlayın
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client.
KritikCVSS 9,8İstismar yokEPSS %2adremsoft · netcrunch16 Ara 2020
- CVE-2019-1448039İzleyin
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication
KritikCVSS 9,8İstismar yokEPSS %1adremsoft · netcrunch16 Ara 2020
- CVE-2019-1447936İzleyin
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution.
YüksekCVSS 8,8İstismar yokEPSS %4adremsoft · netcrunch16 Ara 2020
- CVE-2019-1448336İzleyin
AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure.
YüksekCVSS 8,8İstismar yokEPSS %2adremsoft · netcrunch16 Ara 2020
- CVE-2019-1447626İzleyin
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.
OrtaCVSS 6,5İstismar yokEPSS %1adremsoft · netcrunch16 Ara 2020
- CVE-2019-1447722İzleyin
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwor
OrtaCVSS 5,5İstismar yokEPSS %0adremsoft · netcrunch16 Ara 2020
- CVE-2019-1447821İzleyin
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client.
OrtaCVSS 5,4İstismar yokEPSS %1adremsoft · netcrunch16 Ara 2020
- CVE-2019-1448121İzleyin
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client.
OrtaCVSS 5,4İstismar yokEPSS %0adremsoft · netcrunch16 Ara 2020