Записи r1bbit
10 опубликованных записей вендора r1bbit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-266 Incorrect Privilege Assignment1
- CWE-284 Improper Access Control1
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
29Наблюдать | CVE-2025-25585Эксплойта нет | Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitr1bbit · yimioa · CWE-284 | Высокая7,3 | — | 0,3 % | 18 мар. 2025 г. |
27Наблюдать | CVE-2025-1226Эксплойта нет | ywoa setup.jsp improper authorizationr1bbit · yimioa · CWE-266 | Средняя6,9 | — | 0,8 % | 12 февр. 2025 г. |
24Наблюдать | CVE-2025-25590Эксплойта нет | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.r1bbit · yimioa · CWE-89 | Средняя6,1 | — | 0,2 % | 18 мар. 2025 г. |
24Наблюдать | CVE-2025-25580Эксплойта нет | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.r1bbit · yimioa · CWE-89 | Средняя6,1 | — | 0,2 % | 18 мар. 2025 г. |
24Наблюдать | CVE-2025-25582Эксплойта нет | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xr1bbit · yimioa · CWE-89 | Средняя6,1 | — | 0,2 % | 18 мар. 2025 г. |
21Наблюдать | CVE-2025-1216Эксплойта нет | ywoa OaNoticeMapper.xml selectNoticeList sql injectionr1bbit · yimioa · CWE-74 | Средняя5,3 | — | 0,5 % | 12 февр. 2025 г. |
21Наблюдать | CVE-2025-1227Эксплойта нет | ywoa AddressDao.xml selectList sql injectionr1bbit · yimioa · CWE-74 | Средняя5,3 | — | 0,5 % | 12 февр. 2025 г. |
21Наблюдать | CVE-2025-1224Эксплойта нет | ywoa UserMapper.xml listNameBySql sql injectionr1bbit · yimioa · CWE-74 | Средняя5,3 | — | 0,4 % | 12 февр. 2025 г. |
21Наблюдать | CVE-2025-1225Эксплойта нет | ywoa WXCallBack Interface XMLParse.java extract xml external entity referencer1bbit · yimioa · CWE-610 | Средняя5,3 | — | 0,4 % | 12 февр. 2025 г. |
16Наблюдать | CVE-2025-25586Эксплойта нет | yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.r1bbit · yimioa · CWE-538 | Средняя4,2 | — | 0,2 % | 18 мар. 2025 г. |
- CVE-2025-2558529Наблюдать
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbit
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %r1bbit · yimioa18 мар. 2025 г.
- CVE-2025-122627Наблюдать
ywoa setup.jsp improper authorization
СредняяCVSS 6,9Эксплойта нетEPSS 1 %r1bbit · yimioa12 февр. 2025 г.
- CVE-2025-2559024Наблюдать
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %r1bbit · yimioa18 мар. 2025 г.
- CVE-2025-2558024Наблюдать
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %r1bbit · yimioa18 мар. 2025 г.
- CVE-2025-2558224Наблюдать
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.x
СредняяCVSS 6,1Эксплойта нетEPSS 0 %r1bbit · yimioa18 мар. 2025 г.
- CVE-2025-121621Наблюдать
ywoa OaNoticeMapper.xml selectNoticeList sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %r1bbit · yimioa12 февр. 2025 г.
- CVE-2025-122721Наблюдать
ywoa AddressDao.xml selectList sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %r1bbit · yimioa12 февр. 2025 г.
- CVE-2025-122421Наблюдать
ywoa UserMapper.xml listNameBySql sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 0 %r1bbit · yimioa12 февр. 2025 г.
- CVE-2025-122521Наблюдать
ywoa WXCallBack Interface XMLParse.java extract xml external entity reference
СредняяCVSS 5,3Эксплойта нетEPSS 0 %r1bbit · yimioa12 февр. 2025 г.
- CVE-2025-2558616Наблюдать
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.
СредняяCVSS 4,2Эксплойта нетEPSS 0 %r1bbit · yimioa18 мар. 2025 г.