Записи icz
9 опубликованных записей вендора icz.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-24913Эксплойта нет | SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.icz · matcha invoice · CWE-89 | Высокая8,7 | — | 0,3 % | 8 апр. 2026 г. |
27Наблюдать | CVE-2015-5643Эксплойта нет | The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitraricz · matchasns · CWE-94 | Средняя6,8 | — | 1,3 % | 5 окт. 2015 г. |
27Наблюдать | CVE-2015-5644Эксплойта нет | The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHicz · matchasns · CWE-94 | Средняя6,8 | — | 1,3 % | 5 окт. 2015 г. |
27Наблюдать | CVE-2012-1237Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitraryicz · sencha sns · CWE-352 | Средняя6,8 | — | 0,6 % | 6 апр. 2012 г. |
26Наблюдать | CVE-2015-5645Эксплойта нет | ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.icz · matchasns · CWE-264 | Средняя6,5 | — | 1,3 % | 5 окт. 2015 г. |
26Наблюдать | CVE-2015-5642Эксплойта нет | Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commandsicz · matchasns · CWE-89 | Средняя6,5 | — | 1,0 % | 5 окт. 2015 г. |
20Наблюдать | CVE-2026-33273Эксплойта нет | Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier.icz · matcha invoice · CWE-434 | Средняя5,1 | — | 0,4 % | 8 апр. 2026 г. |
20Наблюдать | CVE-2026-27787Эксплойта нет | Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier.icz · matcha sns · CWE-79 | Средняя5,1 | — | 0,2 % | 8 апр. 2026 г. |
17Наблюдать | CVE-2012-1238Эксплойта нет | Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.icz · sencha sns | Средняя4,3 | — | 1,2 % | 6 апр. 2012 г. |
- CVE-2026-2491334Наблюдать
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %icz · matcha invoice8 апр. 2026 г.
- CVE-2015-564327Наблюдать
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrar
СредняяCVSS 6,8Эксплойта нетEPSS 1 %icz · matchasns5 окт. 2015 г.
- CVE-2015-564427Наблюдать
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PH
СредняяCVSS 6,8Эксплойта нетEPSS 1 %icz · matchasns5 окт. 2015 г.
- CVE-2012-123727Наблюдать
Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary
СредняяCVSS 6,8Эксплойта нетEPSS 1 %icz · sencha sns6 апр. 2012 г.
- CVE-2015-564526Наблюдать
ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %icz · matchasns5 окт. 2015 г.
- CVE-2015-564226Наблюдать
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands
СредняяCVSS 6,5Эксплойта нетEPSS 1 %icz · matchasns5 окт. 2015 г.
- CVE-2026-3327320Наблюдать
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier.
СредняяCVSS 5,1Эксплойта нетEPSS 0 %icz · matcha invoice8 апр. 2026 г.
- CVE-2026-2778720Наблюдать
Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier.
СредняяCVSS 5,1Эксплойта нетEPSS 0 %icz · matcha sns8 апр. 2026 г.
- CVE-2012-123817Наблюдать
Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %icz · sencha sns6 апр. 2012 г.