Записи derbynet
11 опубликованных записей вендора derbynet.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-692 Incomplete Denylist to Cross-Site Scripting1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-31818Эксплойта нет | Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.pderbynet · derbynet · CWE-22 | Критическая9,8 | — | 1,9 % | 12 апр. 2024 г. |
39Наблюдать | CVE-2024-30922Эксплойта нет | SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendederbynet · derbynet · CWE-89 | Критическая9,8 | — | 1,4 % | 18 апр. 2024 г. |
39Наблюдать | CVE-2024-30923Эксплойта нет | SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Docuderbynet · derbynet · CWE-94 | Критическая9,8 | — | 1,4 % | 18 апр. 2024 г. |
32Наблюдать | CVE-2024-30929Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlisderbynet · derbynet · CWE-79 | Высокая8,0 | — | 1,0 % | 18 апр. 2024 г. |
32Наблюдать | CVE-2024-30928Эксплойта нет | SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/qderbynet · derbynet · CWE-89 | Высокая8,1 | — | 0,7 % | 18 апр. 2024 г. |
29Наблюдать | CVE-2024-30920Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.phpderbynet · derbynet · CWE-79 | Высокая7,4 | — | 1,0 % | 18 апр. 2024 г. |
26Наблюдать | CVE-2024-30925Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.derbynet · derbynet · CWE-79 | Средняя6,5 | — | 0,6 % | 18 апр. 2024 г. |
25Наблюдать | CVE-2024-30927Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php componentderbynet · derbynet · CWE-79 | Средняя6,3 | — | 0,6 % | 18 апр. 2024 г. |
21Наблюдать | CVE-2024-30921Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php componentderbynet · derbynet · CWE-79 | Средняя5,4 | — | 0,6 % | 18 апр. 2024 г. |
18Наблюдать | CVE-2024-30926Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.derbynet · derbynet · CWE-79 | Средняя4,6 | — | 0,5 % | 18 апр. 2024 г. |
18Наблюдать | CVE-2024-30924Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.derbynet · derbynet · CWE-692 | Средняя4,6 | — | 0,3 % | 18 апр. 2024 г. |
- CVE-2024-3181840В плане
Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.p
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %derbynet · derbynet12 апр. 2024 г.
- CVE-2024-3092239Наблюдать
SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rende
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092339Наблюдать
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Docu
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092932Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlis
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092832Наблюдать
SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/q
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092029Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092526Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092725Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component
СредняяCVSS 6,3Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092121Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component
СредняяCVSS 5,4Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092618Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.
СредняяCVSS 4,6Эксплойта нетEPSS 1 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-3092418Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
СредняяCVSS 4,6Эксплойта нетEPSS 0 %derbynet · derbynet18 апр. 2024 г.