Перейти к содержимому
Noroxi

Записи derbynet

11 опубликованных записей вендора derbynet.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

11 записей
  • CVE-2024-31818
    40В плане

    Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.p

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    derbynet · derbynet12 апр. 2024 г.

  • CVE-2024-30922
    39Наблюдать

    SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rende

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30923
    39Наблюдать

    SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Docu

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30929
    32Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlis

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30928
    32Наблюдать

    SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/q

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30920
    29Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30925
    26Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30927
    25Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30921
    21Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30926
    18Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.

    СредняяCVSS 4,6Эксплойта нетEPSS 1 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-30924
    18Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    derbynet · derbynet18 апр. 2024 г.