PlexTrac records
11 published records for vendor plextrac.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 72.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-307 Improper Restriction of Excessive Authentication Attempts2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-502 Deserialization of Untrusted Data2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-203 Observable Discrepancy1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-37144No exploit | The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts.plextrac · plextrac · CWE-307 | High8.8 | — | 0.9% | Sep 7, 2022 |
35Monitor | CVE-2024-11833No exploit | Arbitrary Directory Write via Runbooks Artifact Uploadplextrac · plextrac · CWE-22 | High8.9 | — | 0.5% | Dec 13, 2024 |
35Monitor | CVE-2024-11834No exploit | Arbitrary File Write via PTRAC Importplextrac · plextrac · CWE-22 | High8.9 | — | 0.5% | Dec 13, 2024 |
34Monitor | CVE-2024-12687No exploit | Insecure YAML Deserializationplextrac · plextrac · CWE-502 | High8.6 | — | 0.7% | Dec 16, 2024 |
34Monitor | CVE-2024-11837No exploit | Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac allows N1QL Injection.Thisplextrac · plextrac · CWE-89 | High8.6 | — | 0.5% | Dec 13, 2024 |
34Monitor | CVE-2024-11838No exploit | Local File Inclusionplextrac · plextrac · CWE-73 | High8.6 | — | 0.4% | Dec 13, 2024 |
34Monitor | CVE-2024-11839No exploit | Insecure Deserialization via Runbooks Importsplextrac · plextrac · CWE-502 | High8.6 | — | 0.4% | Dec 13, 2024 |
34Monitor | CVE-2024-11836No exploit | Server-side Request Forgeryplextrac · plextrac · CWE-918 | High8.6 | — | 0.3% | Dec 13, 2024 |
30Monitor | CVE-2022-37145No exploit | The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTraplextrac · plextrac · CWE-307 | High7.5 | — | 1.0% | Sep 7, 2022 |
28Monitor | CVE-2024-11835No exploit | Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.plextrac · plextrac · CWE-400 | High7.0 | — | 0.4% | Dec 13, 2024 |
21Monitor | CVE-2022-37146No exploit | The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users coplextrac · plextrac · CWE-203 | Medium5.3 | — | 0.8% | Sep 7, 2022 |
- CVE-2022-3714435Monitor
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts.
HighCVSS 8.8No exploitEPSS 1%plextrac · plextracSep 7, 2022
- CVE-2024-1183335Monitor
Arbitrary Directory Write via Runbooks Artifact Upload
HighCVSS 8.9No exploitEPSS 1%plextrac · plextracDec 13, 2024
- CVE-2024-1183435Monitor
Arbitrary File Write via PTRAC Import
HighCVSS 8.9No exploitEPSS 1%plextrac · plextracDec 13, 2024
- CVE-2024-1268734Monitor
Insecure YAML Deserialization
HighCVSS 8.6No exploitEPSS 1%plextrac · plextracDec 16, 2024
- CVE-2024-1183734Monitor
Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac allows N1QL Injection.This
HighCVSS 8.6No exploitEPSS 0%plextrac · plextracDec 13, 2024
- CVE-2024-1183834Monitor
Local File Inclusion
HighCVSS 8.6No exploitEPSS 0%plextrac · plextracDec 13, 2024
- CVE-2024-1183934Monitor
Insecure Deserialization via Runbooks Imports
HighCVSS 8.6No exploitEPSS 0%plextrac · plextracDec 13, 2024
- CVE-2024-1183634Monitor
Server-side Request Forgery
HighCVSS 8.6No exploitEPSS 0%plextrac · plextracDec 13, 2024
- CVE-2022-3714530Monitor
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTra
HighCVSS 7.5No exploitEPSS 1%plextrac · plextracSep 7, 2022
- CVE-2024-1183528Monitor
Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
HighCVSS 7.0No exploitEPSS 0%plextrac · plextracDec 13, 2024
- CVE-2022-3714621Monitor
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users co
MediumCVSS 5.3No exploitEPSS 1%plextrac · plextracSep 7, 2022