Перейти к содержимому
Noroxi

Записи stimulsoft

9 опубликованных записей вендора stimulsoft.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
33,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

9 записей
  • CVE-2020-15865
    41В плане

    A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-6

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    stimulsoft · reports18 авг. 2020 г.

  • CVE-2024-24398
    40В плане

    Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    stimulsoft · dashboards.php5 февр. 2024 г.

  • CVE-2023-25261
    40В плане

    Certain Stimulsoft GmbH products are affected by: Remote Code Execution.

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    stimulsoft · designer27 мар. 2023 г.

  • CVE-2021-42777
    39Наблюдать

    Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    stimulsoft · reports29 окт. 2022 г.

  • CVE-2023-25262
    30Наблюдать

    Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF).

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    stimulsoft · designer27 мар. 2023 г.

  • CVE-2023-25260
    30Наблюдать

    Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    stimulsoft · designer28 мар. 2023 г.

  • CVE-2024-24396
    24Наблюдать

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrar

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    stimulsoft · dashboard.js5 февр. 2024 г.

  • CVE-2023-25263
    22Наблюдать

    In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decry

    СредняяCVSS 5,5Proof of conceptEPSS 0 %

    stimulsoft · designer27 мар. 2023 г.

  • CVE-2024-24397
    21Наблюдать

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrar

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    stimulsoft · dashboards.js5 февр. 2024 г.