codehaus-plexus kayıtları
codehaus-plexus üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-1000487Kavram kanıtı | Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.codehaus-plexus · plexus-utils · CWE-78 | Kritik9,8 | — | %6,5 | 3 Oca 2018 |
40Planlayın | CVE-2023-37460Kavram kanıtı | Plexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchivercodehaus-plexus · plexus-archiver · CWE-22 | Kritik9,8 | — | %2,5 | 25 Tem 2023 |
35İzleyin | CVE-2025-67030İstismar yok | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2dcodehaus-plexus · plexus-utils · CWE-22 | Yüksek8,8 | — | %0,7 | 25 Mar 2026 |
30İzleyin | CVE-2022-4244Kavram kanıtı | Codehaus-plexus: directory traversalcodehaus-plexus · plexus-utils · CWE-22 | Yüksek7,5 | — | %1,3 | 25 Eyl 2023 |
25İzleyin | CVE-2018-1002200Kavram kanıtı | plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) codehaus-plexus · plexus-archiver · CWE-22 | Orta5,5 | — | %11,6 | 25 Tem 2018 |
17İzleyin | CVE-2022-4245İstismar yok | Codehaus-plexus: xml external entity (xxe) injectioncodehaus-plexus · plexus-utils · CWE-91 | Orta4,3 | — | %0,7 | 25 Eyl 2023 |
- CVE-2017-100048741Planlayın
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
KritikCVSS 9,8Kavram kanıtıEPSS %6codehaus-plexus · plexus-utils3 Oca 2018
- CVE-2023-3746040Planlayın
Plexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchiver
KritikCVSS 9,8Kavram kanıtıEPSS %2codehaus-plexus · plexus-archiver25 Tem 2023
- CVE-2025-6703035İzleyin
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d
YüksekCVSS 8,8İstismar yokEPSS %1codehaus-plexus · plexus-utils25 Mar 2026
- CVE-2022-424430İzleyin
Codehaus-plexus: directory traversal
YüksekCVSS 7,5Kavram kanıtıEPSS %1codehaus-plexus · plexus-utils25 Eyl 2023
- CVE-2018-100220025İzleyin
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash)
OrtaCVSS 5,5Kavram kanıtıEPSS %12codehaus-plexus · plexus-archiver25 Tem 2018
- CVE-2022-424517İzleyin
Codehaus-plexus: xml external entity (xxe) injection
OrtaCVSS 4,3İstismar yokEPSS %1codehaus-plexus · plexus-utils25 Eyl 2023