SecurEnvoy kayıtları
securenvoy üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-862 Missing Authorization1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-7702Kavram kanıtı | SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arsecurenvoy · securmail · CWE-862 | Kritik9,1 | — | %14,0 | 14 Mar 2018 |
37İzleyin | CVE-2020-13376İstismar yok | SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cooksecurenvoy · securmail · CWE-22 | Kritik9,0 | — | %3,5 | 7 Ağu 2020 |
34İzleyin | CVE-2018-7705Kavram kanıtı | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrsecurenvoy · securmail · CWE-22 | Yüksek8,1 | — | %6,0 | 14 Mar 2018 |
31İzleyin | CVE-2024-37393Kavram kanıtı | Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input.securenvoy · multi-factor authentication solutions · CWE-319 | Yüksek7,5 | — | %3,3 | 10 Haz 2024 |
28İzleyin | CVE-2018-7706Kavram kanıtı | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messagessecurenvoy · securmail · CWE-22 | Orta6,5 | — | %6,7 | 14 Mar 2018 |
28İzleyin | CVE-2018-18466İstismar yok | An issue was discovered in SecurEnvoy SecurAccess 9.3.502.securenvoy · securaccess · CWE-532 | Yüksek7,0 | — | %0,3 | 21 Mar 2019 |
27İzleyin | CVE-2018-7704Kavram kanıtı | SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a replysecurenvoy · securmail · CWE-200 | Orta6,5 | — | %4,6 | 14 Mar 2018 |
27İzleyin | CVE-2018-7701Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authesecurenvoy · securmail · CWE-352 | Orta6,5 | — | %2,9 | 14 Mar 2018 |
25İzleyin | CVE-2018-7703Kavram kanıtı | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTsecurenvoy · securmail · CWE-79 | Orta6,1 | — | %3,9 | 14 Mar 2018 |
25İzleyin | CVE-2018-7707Kavram kanıtı | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTsecurenvoy · securmail · CWE-79 | Orta6,1 | — | %2,6 | 14 Mar 2018 |
- CVE-2018-770240Planlayın
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to ar
KritikCVSS 9,1Kavram kanıtıEPSS %14securenvoy · securmail14 Mar 2018
- CVE-2020-1337637İzleyin
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cook
KritikCVSS 9,0İstismar yokEPSS %4securenvoy · securmail7 Ağu 2020
- CVE-2018-770534İzleyin
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitr
YüksekCVSS 8,1Kavram kanıtıEPSS %6securenvoy · securmail14 Mar 2018
- CVE-2024-3739331İzleyin
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input.
YüksekCVSS 7,5Kavram kanıtıEPSS %3securenvoy · multi-factor authentication solutions10 Haz 2024
- CVE-2018-770628İzleyin
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages
OrtaCVSS 6,5Kavram kanıtıEPSS %7securenvoy · securmail14 Mar 2018
- CVE-2018-1846628İzleyin
An issue was discovered in SecurEnvoy SecurAccess 9.3.502.
YüksekCVSS 7,0İstismar yokEPSS %0securenvoy · securaccess21 Mar 2019
- CVE-2018-770427İzleyin
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a reply
OrtaCVSS 6,5Kavram kanıtıEPSS %5securenvoy · securmail14 Mar 2018
- CVE-2018-770127İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authe
OrtaCVSS 6,5Kavram kanıtıEPSS %3securenvoy · securmail14 Mar 2018
- CVE-2018-770325İzleyin
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HT
OrtaCVSS 6,1Kavram kanıtıEPSS %4securenvoy · securmail14 Mar 2018
- CVE-2018-770725İzleyin
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HT
OrtaCVSS 6,1Kavram kanıtıEPSS %3securenvoy · securmail14 Mar 2018