Combodo kayıtları
combodo üreticisine ait 82 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %18,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-863 Incorrect Authorization3
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
82 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-39216İstismar yok | Combodo iTop's weak password reset token leads to account takeovercombodo · itop · CWE-330 | Kritik9,8 | — | %0,9 | 14 Mar 2023 |
39İzleyin | CVE-2023-48710İstismar yok | iTop limit pages/exec.php script to PHP filescombodo · itop · CWE-552 | Kritik9,8 | — | %0,7 | 15 Nis 2024 |
38İzleyin | CVE-2022-39214İstismar yok | Authenticated users of Combodo iTop can take over any accountcombodo · itop · CWE-863 | Yüksek7,5 | — | %25,6 | 14 Mar 2023 |
38İzleyin | CVE-2024-54139İstismar yok | Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parametercombodo · itop · CWE-79 | Kritik9,6 | — | %0,2 | 13 Ara 2024 |
37İzleyin | CVE-2022-24780Kavram kanıtı | Code Injection in Combodo iTopcombodo · itop · CWE-94 | Yüksek8,8 | — | %5,7 | 5 Nis 2022 |
35İzleyin | CVE-2021-21406İstismar yok | Command Injection vulnerability in the Setup Wizardcombodo · itop · CWE-77 | Yüksek8,8 | — | %1,0 | 21 Tem 2021 |
35İzleyin | CVE-2024-52002Kavram kanıtı | Cross-Site Request Forgery (CSRF) in several iTop pagescombodo · itop · CWE-352 | Yüksek8,8 | — | %0,7 | 8 Kas 2024 |
35İzleyin | CVE-2024-51740İstismar yok | SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTopcombodo · itop · CWE-918 | Yüksek8,8 | — | %0,5 | 5 Kas 2024 |
35İzleyin | CVE-2020-12781İstismar yok | Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request combodo · itop · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Ağu 2020 |
35İzleyin | CVE-2021-32776İstismar yok | No CSRF form token cleanup on Windows serverscombodo · itop · CWE-352 | Yüksek8,8 | — | %0,4 | 21 Tem 2021 |
35İzleyin | CVE-2024-31998İstismar yok | CSRF security issue on CSV import in Combodo iTopcombodo · itop · CWE-352 | Yüksek8,8 | — | %0,2 | 4 Kas 2024 |
34İzleyin | CVE-2025-24022İstismar yok | iTop server vulnerable to portal code injectioncombodo · itop · CWE-78 | Yüksek8,5 | — | %0,6 | 14 May 2025 |
34İzleyin | CVE-2025-47286İstismar yok | Combodo iTop vulnerable to Remote Code Execution in the backup creation functionalitycombodo · itop · CWE-74 | Yüksek8,6 | — | %0,5 | 10 Kas 2025 |
32İzleyin | CVE-2019-10863Kavram kanıtı | A command injection vulnerability exists in TeemIp versions before 2.4.0.combodo · teemip · CWE-94 | Yüksek7,2 | — | %13,4 | 4 Nis 2019 |
32İzleyin | CVE-2019-19821İstismar yok | A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information acombodo · itop · CWE-79 | Yüksek8,1 | — | %1,4 | 16 Mar 2020 |
32İzleyin | CVE-2019-11215İstismar yok | In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling combodo · itop · CWE-79 | Yüksek8,1 | — | %1,2 | 14 Şub 2020 |
32İzleyin | CVE-2023-48709İstismar yok | iTop vulnerable to potential formula injection in Excel/CSV export filecombodo · itop · CWE-74 | Yüksek8,0 | — | %1,0 | 15 Nis 2024 |
32İzleyin | CVE-2021-41245İstismar yok | Possible Cross-Site Request Forgery in Combodo iTopcombodo · itop · CWE-352 | Yüksek8,1 | — | %0,7 | 5 Nis 2022 |
31İzleyin | CVE-2023-47489İstismar yok | CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to thecombodo · itop | Yüksek7,8 | — | %0,4 | 9 Kas 2023 |
30İzleyin | CVE-2018-10642İstismar yok | Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing tcombodo · itop · CWE-94 | Yüksek7,2 | — | %7,4 | 2 May 2018 |
30İzleyin | CVE-2021-32663İstismar yok | Unauthorized setup leads to SSRF in Combodo/iTopcombodo · itop · CWE-918 | Yüksek7,5 | — | %1,5 | 19 Eki 2021 |
30İzleyin | CVE-2019-13967İstismar yok | iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile opecombodo · itop | Yüksek7,5 | — | %1,3 | 14 Şub 2020 |
30İzleyin | CVE-2020-12777İstismar yok | Combodo iTop - Broken Access Controlcombodo · itop · CWE-200 | Yüksek7,5 | — | %1,3 | 9 Ağu 2020 |
30İzleyin | CVE-2020-12780İstismar yok | Combodo iTop - Security Misconfigurationcombodo · itop · CWE-863 | Yüksek7,5 | — | %1,2 | 9 Ağu 2020 |
30İzleyin | CVE-2020-4079İstismar yok | Information disclosure vulnerability in iTopcombodo · itop · CWE-200 | Yüksek7,7 | — | %0,9 | 12 Oca 2021 |
- CVE-2022-3921639İzleyin
Combodo iTop's weak password reset token leads to account takeover
KritikCVSS 9,8İstismar yokEPSS %1combodo · itop14 Mar 2023
- CVE-2023-4871039İzleyin
iTop limit pages/exec.php script to PHP files
KritikCVSS 9,8İstismar yokEPSS %1combodo · itop15 Nis 2024
- CVE-2022-3921438İzleyin
Authenticated users of Combodo iTop can take over any account
YüksekCVSS 7,5İstismar yokEPSS %26combodo · itop14 Mar 2023
- CVE-2024-5413938İzleyin
Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter
KritikCVSS 9,6İstismar yokEPSS %0combodo · itop13 Ara 2024
- CVE-2022-2478037İzleyin
Code Injection in Combodo iTop
YüksekCVSS 8,8Kavram kanıtıEPSS %6combodo · itop5 Nis 2022
- CVE-2021-2140635İzleyin
Command Injection vulnerability in the Setup Wizard
YüksekCVSS 8,8İstismar yokEPSS %1combodo · itop21 Tem 2021
- CVE-2024-5200235İzleyin
Cross-Site Request Forgery (CSRF) in several iTop pages
YüksekCVSS 8,8Kavram kanıtıEPSS %1combodo · itop8 Kas 2024
- CVE-2024-5174035İzleyin
SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop
YüksekCVSS 8,8İstismar yokEPSS %1combodo · itop5 Kas 2024
- CVE-2020-1278135İzleyin
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request
YüksekCVSS 8,8İstismar yokEPSS %0combodo · itop9 Ağu 2020
- CVE-2021-3277635İzleyin
No CSRF form token cleanup on Windows servers
YüksekCVSS 8,8İstismar yokEPSS %0combodo · itop21 Tem 2021
- CVE-2024-3199835İzleyin
CSRF security issue on CSV import in Combodo iTop
YüksekCVSS 8,8İstismar yokEPSS %0combodo · itop4 Kas 2024
- CVE-2025-2402234İzleyin
iTop server vulnerable to portal code injection
YüksekCVSS 8,5İstismar yokEPSS %1combodo · itop14 May 2025
- CVE-2025-4728634İzleyin
Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality
YüksekCVSS 8,6İstismar yokEPSS %0combodo · itop10 Kas 2025
- CVE-2019-1086332İzleyin
A command injection vulnerability exists in TeemIp versions before 2.4.0.
YüksekCVSS 7,2Kavram kanıtıEPSS %13combodo · teemip4 Nis 2019
- CVE-2019-1982132İzleyin
A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information a
YüksekCVSS 8,1İstismar yokEPSS %1combodo · itop16 Mar 2020
- CVE-2019-1121532İzleyin
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling
YüksekCVSS 8,1İstismar yokEPSS %1combodo · itop14 Şub 2020
- CVE-2023-4870932İzleyin
iTop vulnerable to potential formula injection in Excel/CSV export file
YüksekCVSS 8,0İstismar yokEPSS %1combodo · itop15 Nis 2024
- CVE-2021-4124532İzleyin
Possible Cross-Site Request Forgery in Combodo iTop
YüksekCVSS 8,1İstismar yokEPSS %1combodo · itop5 Nis 2022
- CVE-2023-4748931İzleyin
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the
YüksekCVSS 7,8İstismar yokEPSS %0combodo · itop9 Kas 2023
- CVE-2018-1064230İzleyin
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing t
YüksekCVSS 7,2İstismar yokEPSS %7combodo · itop2 May 2018
- CVE-2021-3266330İzleyin
Unauthorized setup leads to SSRF in Combodo/iTop
YüksekCVSS 7,5İstismar yokEPSS %1combodo · itop19 Eki 2021
- CVE-2019-1396730İzleyin
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile ope
YüksekCVSS 7,5İstismar yokEPSS %1combodo · itop14 Şub 2020
- CVE-2020-1277730İzleyin
Combodo iTop - Broken Access Control
YüksekCVSS 7,5İstismar yokEPSS %1combodo · itop9 Ağu 2020
- CVE-2020-1278030İzleyin
Combodo iTop - Security Misconfiguration
YüksekCVSS 7,5İstismar yokEPSS %1combodo · itop9 Ağu 2020
- CVE-2020-407930İzleyin
Information disclosure vulnerability in iTop
YüksekCVSS 7,7İstismar yokEPSS %1combodo · itop12 Oca 2021