Записи erxes
4 опубликованных записей вендора erxes.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-284 Improper Access Control1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-32853Proof of concept | Erxes vulnerable to Cross-site Scriptingerxes · erxes · CWE-79 | Критическая9,6 | — | 3,1 % | 20 февр. 2023 г. |
39Наблюдать | CVE-2024-57190Эксплойта нет | Erxes <1.6.1 is vulnerable to Incorrect Access Control.erxes · erxes · CWE-284 | Критическая9,8 | — | 0,6 % | 10 июн. 2025 г. |
21Наблюдать | CVE-2024-57186Эксплойта нет | In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-fileerxes · erxes · CWE-22 | Средняя5,4 | — | 0,4 % | 10 июн. 2025 г. |
21Наблюдать | CVE-2024-57189Эксплойта нет | In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHisterxes · erxes · CWE-22 | Средняя5,4 | — | 0,4 % | 10 июн. 2025 г. |
- CVE-2021-3285339Наблюдать
Erxes vulnerable to Cross-site Scripting
КритическаяCVSS 9,6Proof of conceptEPSS 3 %erxes · erxes20 февр. 2023 г.
- CVE-2024-5719039Наблюдать
Erxes <1.6.1 is vulnerable to Incorrect Access Control.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %erxes · erxes10 июн. 2025 г.
- CVE-2024-5718621Наблюдать
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file
СредняяCVSS 5,4Эксплойта нетEPSS 0 %erxes · erxes10 июн. 2025 г.
- CVE-2024-5718921Наблюдать
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHist
СредняяCVSS 5,4Эксплойта нетEPSS 0 %erxes · erxes10 июн. 2025 г.