StrangeBee kayıtları
strangebee üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-306 Missing Authentication for Critical Function1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-39069İstismar yok | An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentstrangebee · cortex · CWE-287 | Kritik9,8 | — | %0,9 | 11 Eyl 2023 |
36İzleyin | CVE-2017-18376İstismar yok | An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write accestrangebee · thehive · CWE-264 | Yüksek8,8 | — | %1,9 | 2 Haz 2019 |
27İzleyin | CVE-2026-63098İstismar yok | TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpointstrangebee · thehive · CWE-306 | Orta6,9 | — | %0,4 | 17 Tem 2026 |
21İzleyin | CVE-2024-22876İstismar yok | StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which strangebee · thehive · CWE-79 | Orta5,4 | — | %0,3 | 19 Oca 2024 |
21İzleyin | CVE-2024-22877İstismar yok | StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality.strangebee · thehive · CWE-79 | Orta5,4 | — | %0,3 | 19 Oca 2024 |
- CVE-2023-3906939İzleyin
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authent
KritikCVSS 9,8İstismar yokEPSS %1strangebee · cortex11 Eyl 2023
- CVE-2017-1837636İzleyin
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write acce
YüksekCVSS 8,8İstismar yokEPSS %2strangebee · thehive2 Haz 2019
- CVE-2026-6309827İzleyin
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
OrtaCVSS 6,9İstismar yokEPSS %0strangebee · thehive17 Tem 2026
- CVE-2024-2287621İzleyin
StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which
OrtaCVSS 5,4İstismar yokEPSS %0strangebee · thehive19 Oca 2024
- CVE-2024-2287721İzleyin
StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality.
OrtaCVSS 5,4İstismar yokEPSS %0strangebee · thehive19 Oca 2024