Записи eramba
11 опубликованных записей вендора eramba.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 9,1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 9,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-20 Improper Input Validation1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2023-36255Готовый эксплойт | An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path eramba · eramba · CWE-94 | Высокая8,8 | — | 53,1 % | 2 авг. 2023 г. |
39Наблюдать | CVE-2020-25105Эксплойта нет | eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).eramba · eramba · CWE-640 | Критическая9,8 | — | 1,1 % | 3 сент. 2020 г. |
26Наблюдать | CVE-2025-55462Proof of concept | A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in teramba · eramba · CWE-942 | Средняя6,5 | — | 0,4 % | 13 янв. 2026 г. |
24Наблюдать | CVE-2018-7894Эксплойта нет | Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)eramba · eramba · CWE-79 | Средняя6,1 | — | 0,7 % | 9 мар. 2018 г. |
24Наблюдать | CVE-2018-7741Эксплойта нет | Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.eramba · eramba · CWE-79 | Средняя6,1 | — | 0,7 % | 7 мар. 2018 г. |
24Наблюдать | CVE-2018-7996Эксплойта нет | Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.eramba · eramba · CWE-79 | Средняя6,1 | — | 0,7 % | 9 мар. 2018 г. |
24Наблюдать | CVE-2018-7997Эксплойта нет | Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file pollutederamba · eramba · CWE-79 | Средняя6,1 | — | 0,6 % | 9 мар. 2018 г. |
21Наблюдать | CVE-2020-25104Эксплойта нет | eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.eramba · eramba · CWE-79 | Средняя5,4 | — | 0,6 % | 3 сент. 2020 г. |
21Наблюдать | CVE-2022-43342Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary weeramba · eramba · CWE-79 | Средняя5,4 | — | 0,5 % | 14 нояб. 2022 г. |
21Наблюдать | CVE-2024-27593Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attCWE-79 | Средняя5,4 | — | 0,3 % | 15 мая 2024 г. |
17Наблюдать | CVE-2020-28031Эксплойта нет | eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.eramba · eramba · CWE-20 | Средняя4,3 | — | 0,6 % | 2 нояб. 2020 г. |
- CVE-2023-3625551В плане
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path
ВысокаяCVSS 8,8Готовый эксплойтEPSS 53 %eramba · eramba2 авг. 2023 г.
- CVE-2020-2510539Наблюдать
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eramba · eramba3 сент. 2020 г.
- CVE-2025-5546226Наблюдать
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in t
СредняяCVSS 6,5Proof of conceptEPSS 0 %eramba · eramba13 янв. 2026 г.
- CVE-2018-789424Наблюдать
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eramba · eramba9 мар. 2018 г.
- CVE-2018-774124Наблюдать
Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eramba · eramba7 мар. 2018 г.
- CVE-2018-799624Наблюдать
Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eramba · eramba9 мар. 2018 г.
- CVE-2018-799724Наблюдать
Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eramba · eramba9 мар. 2018 г.
- CVE-2020-2510421Наблюдать
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %eramba · eramba3 сент. 2020 г.
- CVE-2022-4334221Наблюдать
A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary we
СредняяCVSS 5,4Эксплойта нетEPSS 1 %eramba · eramba14 нояб. 2022 г.
- CVE-2024-2759321Наблюдать
A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated att
СредняяCVSS 5,4Эксплойта нетEPSS 0 %15 мая 2024 г.
- CVE-2020-2803117Наблюдать
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %eramba · eramba2 нояб. 2020 г.