mk-auth kayıtları
mk-auth üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-287 Improper Authentication1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-14072İstismar yok | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-78 | Kritik9,8 | — | %3,4 | 29 Haz 2020 |
40Planlayın | CVE-2020-14070İstismar yok | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-287 | Kritik9,8 | — | %1,8 | 29 Haz 2020 |
39İzleyin | CVE-2020-14068İstismar yok | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-89 | Kritik9,8 | — | %1,1 | 29 Haz 2020 |
35İzleyin | CVE-2023-27246İstismar yok | An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a cmk-auth · mk-auth · CWE-434 | Yüksek8,8 | — | %0,8 | 28 Mar 2023 |
35İzleyin | CVE-2021-21495İstismar yok | MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.mk-auth · mk-auth · CWE-352 | Yüksek8,8 | — | %0,5 | 3 Oca 2021 |
27İzleyin | CVE-2020-14069İstismar yok | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-89 | Orta6,8 | — | %0,4 | 29 Haz 2020 |
24İzleyin | CVE-2020-14071İstismar yok | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-79 | Orta6,1 | — | %0,7 | 29 Haz 2020 |
19İzleyin | CVE-2021-21494İstismar yok | MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter.mk-auth · mk-auth · CWE-732 | Orta4,8 | — | %0,5 | 3 Oca 2021 |
17İzleyin | CVE-2021-3005İstismar yok | MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice nmk-auth · mk-auth | Orta4,3 | — | %0,9 | 3 Oca 2021 |
- CVE-2020-1407240Planlayın
An issue was discovered in MK-AUTH 19.01.
KritikCVSS 9,8İstismar yokEPSS %3mk-auth · mk-auth29 Haz 2020
- CVE-2020-1407040Planlayın
An issue was discovered in MK-AUTH 19.01.
KritikCVSS 9,8İstismar yokEPSS %2mk-auth · mk-auth29 Haz 2020
- CVE-2020-1406839İzleyin
An issue was discovered in MK-AUTH 19.01.
KritikCVSS 9,8İstismar yokEPSS %1mk-auth · mk-auth29 Haz 2020
- CVE-2023-2724635İzleyin
An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c
YüksekCVSS 8,8İstismar yokEPSS %1mk-auth · mk-auth28 Mar 2023
- CVE-2021-2149535İzleyin
MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.
YüksekCVSS 8,8İstismar yokEPSS %1mk-auth · mk-auth3 Oca 2021
- CVE-2020-1406927İzleyin
An issue was discovered in MK-AUTH 19.01.
OrtaCVSS 6,8İstismar yokEPSS %0mk-auth · mk-auth29 Haz 2020
- CVE-2020-1407124İzleyin
An issue was discovered in MK-AUTH 19.01.
OrtaCVSS 6,1İstismar yokEPSS %1mk-auth · mk-auth29 Haz 2020
- CVE-2021-2149419İzleyin
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter.
OrtaCVSS 4,8İstismar yokEPSS %1mk-auth · mk-auth3 Oca 2021
- CVE-2021-300517İzleyin
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice n
OrtaCVSS 4,3İstismar yokEPSS %1mk-auth · mk-auth3 Oca 2021