Записи stimulsoft
9 опубликованных записей вендора stimulsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 33,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-552 Files or Directories Accessible to External Parties1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-15865Эксплойта нет | A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-6stimulsoft · reports · CWE-94 | Критическая9,8 | — | 5,1 % | 18 авг. 2020 г. |
40В плане | CVE-2024-24398Proof of concept | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrarystimulsoft · dashboards.php · CWE-22 | Критическая9,8 | — | 2,0 % | 5 февр. 2024 г. |
40В плане | CVE-2023-25261Proof of concept | Certain Stimulsoft GmbH products are affected by: Remote Code Execution.stimulsoft · designer · CWE-94 | Критическая9,8 | — | 1,9 % | 27 мар. 2023 г. |
39Наблюдать | CVE-2021-42777Эксплойта нет | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macstimulsoft · reports · CWE-209 | Критическая9,8 | — | 1,0 % | 29 окт. 2022 г. |
30Наблюдать | CVE-2023-25262Proof of concept | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF).stimulsoft · designer · CWE-918 | Высокая7,5 | — | 0,9 % | 27 мар. 2023 г. |
30Наблюдать | CVE-2023-25260Proof of concept | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.stimulsoft · designer · CWE-552 | Высокая7,5 | — | 0,8 % | 28 мар. 2023 г. |
24Наблюдать | CVE-2024-24396Proof of concept | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrarstimulsoft · dashboard.js · CWE-79 | Средняя6,1 | — | 0,8 % | 5 февр. 2024 г. |
22Наблюдать | CVE-2023-25263Proof of concept | In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrystimulsoft · designer · CWE-312 | Средняя5,5 | — | 0,2 % | 27 мар. 2023 г. |
21Наблюдать | CVE-2024-24397Proof of concept | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrarstimulsoft · dashboards.js · CWE-79 | Средняя5,4 | — | 0,8 % | 5 февр. 2024 г. |
- CVE-2020-1586541В плане
A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-6
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %stimulsoft · reports18 авг. 2020 г.
- CVE-2024-2439840В плане
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary
КритическаяCVSS 9,8Proof of conceptEPSS 2 %stimulsoft · dashboards.php5 февр. 2024 г.
- CVE-2023-2526140В плане
Certain Stimulsoft GmbH products are affected by: Remote Code Execution.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %stimulsoft · designer27 мар. 2023 г.
- CVE-2021-4277739Наблюдать
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %stimulsoft · reports29 окт. 2022 г.
- CVE-2023-2526230Наблюдать
Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF).
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %stimulsoft · designer27 мар. 2023 г.
- CVE-2023-2526030Наблюдать
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %stimulsoft · designer28 мар. 2023 г.
- CVE-2024-2439624Наблюдать
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrar
СредняяCVSS 6,1Proof of conceptEPSS 1 %stimulsoft · dashboard.js5 февр. 2024 г.
- CVE-2023-2526322Наблюдать
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decry
СредняяCVSS 5,5Proof of conceptEPSS 0 %stimulsoft · designer27 мар. 2023 г.
- CVE-2024-2439721Наблюдать
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrar
СредняяCVSS 5,4Proof of conceptEPSS 1 %stimulsoft · dashboards.js5 февр. 2024 г.