bladex kayıtları
bladex üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-284 Improper Access Control2
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2023-40787İstismar yok | In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL bladex · springblade · CWE-89 | Kritik9,8 | — | %18,2 | 29 Ağu 2023 |
40Planlayın | CVE-2022-27360İstismar yok | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.bladex · springblade · CWE-89 | Kritik9,8 | — | %2,0 | 5 May 2022 |
39İzleyin | CVE-2020-16165İstismar yok | The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause.bladex · springblade · CWE-89 | Kritik9,8 | — | %1,2 | 30 Tem 2020 |
39İzleyin | CVE-2023-47458İstismar yok | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.bladex · springblade · CWE-862 | Kritik9,8 | — | %0,6 | 2 Oca 2024 |
39İzleyin | CVE-2025-70983İstismar yok | Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.bladex · springblade · CWE-284 | Kritik9,9 | — | %0,4 | 23 Oca 2026 |
39İzleyin | CVE-2025-70982İstismar yok | Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sbladex · springblade · CWE-284 | Kritik9,9 | — | %0,3 | 26 Oca 2026 |
30İzleyin | CVE-2024-33332İstismar yok | An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenantbladex · springblade · CWE-89 | Yüksek7,5 | — | %0,7 | 30 Nis 2024 |
21İzleyin | CVE-2023-40788İstismar yok | SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorizbladex · springblade · CWE-668 | Orta5,3 | — | %0,8 | 18 Eyl 2023 |
21İzleyin | CVE-2024-8023İstismar yok | chillzhuang SpringBlade list sql injectionbladex · springblade · CWE-89 | Orta5,3 | — | %0,6 | 20 Ağu 2024 |
- CVE-2023-4078744Planlayın
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL
KritikCVSS 9,8İstismar yokEPSS %18bladex · springblade29 Ağu 2023
- CVE-2022-2736040Planlayın
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
KritikCVSS 9,8İstismar yokEPSS %2bladex · springblade5 May 2022
- CVE-2020-1616539İzleyin
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause.
KritikCVSS 9,8İstismar yokEPSS %1bladex · springblade30 Tem 2020
- CVE-2023-4745839İzleyin
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
KritikCVSS 9,8İstismar yokEPSS %1bladex · springblade2 Oca 2024
- CVE-2025-7098339İzleyin
Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.
KritikCVSS 9,9İstismar yokEPSS %0bladex · springblade23 Oca 2026
- CVE-2025-7098239İzleyin
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import s
KritikCVSS 9,9İstismar yokEPSS %0bladex · springblade26 Oca 2026
- CVE-2024-3333230İzleyin
An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant
YüksekCVSS 7,5İstismar yokEPSS %1bladex · springblade30 Nis 2024
- CVE-2023-4078821İzleyin
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthoriz
OrtaCVSS 5,3İstismar yokEPSS %1bladex · springblade18 Eyl 2023
- CVE-2024-802321İzleyin
chillzhuang SpringBlade list sql injection
OrtaCVSS 5,3İstismar yokEPSS %1bladex · springblade20 Ağu 2024