Записи craftycontrol
8 опубликованных записей вендора craftycontrol.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-35 Path Traversal: '.../...//'1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2025-14700Proof of concept | Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controllercraftycontrol · crafty controller · CWE-1336 | Критическая9,9 | — | 6,6 % | 16 дек. 2025 г. |
36Наблюдать | CVE-2026-13716Эксплойта нет | Path Traversal: '.../...//' in Crafty Controllercraftycontrol · crafty controller · CWE-35 | Критическая9,1 | — | 0,8 % | 11 авг. 2026 г. |
36Наблюдать | CVE-2026-5652Эксплойта нет | Authorization Bypass Through User-Controlled Key in Crafty Controllercraftycontrol · crafty controller · CWE-639 | Критическая9,0 | — | 0,5 % | 21 апр. 2026 г. |
35Наблюдать | CVE-2026-0963Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controllercraftycontrol · crafty controller · CWE-22 | Высокая8,8 | — | 0,8 % | 30 янв. 2026 г. |
35Наблюдать | CVE-2026-0805Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controllercraftycontrol · crafty controller · CWE-22 | Высокая8,8 | — | 0,7 % | 30 янв. 2026 г. |
30Наблюдать | CVE-2024-1064Эксплойта нет | Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4craftycontrol · crafty controller · CWE-644 | Высокая7,5 | — | 0,8 % | 3 февр. 2024 г. |
28Наблюдать | CVE-2025-14701Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controllercraftycontrol · crafty controller · CWE-79 | Высокая7,1 | — | 0,3 % | 16 дек. 2025 г. |
21Наблюдать | CVE-2025-5990Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controllercraftycontrol · crafty controller · CWE-79 | Средняя5,4 | — | 0,3 % | 15 июн. 2025 г. |
- CVE-2025-1470041В плане
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
КритическаяCVSS 9,9Proof of conceptEPSS 7 %craftycontrol · crafty controller16 дек. 2025 г.
- CVE-2026-1371636Наблюдать
Path Traversal: '.../...//' in Crafty Controller
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %craftycontrol · crafty controller11 авг. 2026 г.
- CVE-2026-565236Наблюдать
Authorization Bypass Through User-Controlled Key in Crafty Controller
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %craftycontrol · crafty controller21 апр. 2026 г.
- CVE-2026-096335Наблюдать
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %craftycontrol · crafty controller30 янв. 2026 г.
- CVE-2026-080535Наблюдать
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %craftycontrol · crafty controller30 янв. 2026 г.
- CVE-2024-106430Наблюдать
Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %craftycontrol · crafty controller3 февр. 2024 г.
- CVE-2025-1470128Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %craftycontrol · crafty controller16 дек. 2025 г.
- CVE-2025-599021Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller
СредняяCVSS 5,4Эксплойта нетEPSS 0 %craftycontrol · crafty controller15 июн. 2025 г.