Перейти к содержимому
Noroxi

Записи MITRE

15 опубликованных записей вендора mitre.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
6,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

15 записей
  • CVE-2021-42561
    41В плане

    An issue was discovered in CALDERA 2.8.1.

    ВысокаяCVSS 8,8Proof of conceptEPSS 20 %

    mitre · caldera12 янв. 2022 г.

  • CVE-2008-4704
    41В плане

    PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via

    КритическаяCVSS 10,0Proof of conceptEPSS 4 %

    mitre · sezhoo23 окт. 2008 г.

  • CVE-2020-19907
    36Наблюдать

    A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command o

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    mitre · caldera12 июл. 2021 г.

  • CVE-2021-42560
    36Наблюдать

    An issue was discovered in CALDERA 2.9.0.

    ВысокаяCVSS 8,8Proof of conceptEPSS 2 %

    mitre · caldera12 янв. 2022 г.

  • CVE-2021-42559
    36Наблюдать

    An issue was discovered in CALDERA 2.8.1.

    ВысокаяCVSS 8,8Proof of conceptEPSS 2 %

    mitre · caldera12 янв. 2022 г.

  • CVE-2021-42562
    32Наблюдать

    An issue was discovered in CALDERA 2.8.1.

    ВысокаяCVSS 8,1Proof of conceptEPSS 1 %

    mitre · caldera12 янв. 2022 г.

  • CVE-2022-31004
    30Наблюдать

    Potential secrets being logged to disk in CVE Services

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mitre · cve-services2 июн. 2022 г.

  • CVE-2021-46561
    28Наблюдать

    controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organiza

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    mitre · cve services26 янв. 2022 г.

  • CVE-2021-42558
    24Наблюдать

    An issue was discovered in CALDERA 2.8.1.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    mitre · caldera12 янв. 2022 г.

  • CVE-2022-40606
    24Наблюдать

    MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability th

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    mitre · caldera17 окт. 2022 г.

  • CVE-2022-40605
    24Наблюдать

    MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability th

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    mitre · caldera17 окт. 2022 г.

  • CVE-2020-10807
    21Наблюдать

    auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host heade

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    mitre · caldera22 мар. 2020 г.

  • CVE-2020-14462
    21Наблюдать

    CALDERA 2.7.0 allows XSS via the Operation Name box.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    mitre · caldera19 июн. 2020 г.

  • CVE-2022-41139
    21Наблюдать

    MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary com

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    mitre · caldera17 окт. 2022 г.

  • CVE-2023-51792
    13Наблюдать

    Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the

    НизкаяCVSS 3,3Эксплойта нетEPSS 0 %

    19 апр. 2024 г.