TeamPass kayıtları
teampass üreticisine ait 50 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %62
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-269 Improper Privilege Management3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-266 Incorrect Privilege Assignment2
- CWE-264 Permissions, Privileges, and Access Controls2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
50 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2015-7564Kavram kanıtı | Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) iteampass · teampass · CWE-89 | Kritik9,8 | — | %3,4 | 12 Nis 2017 |
40Planlayın | CVE-2019-1000001İstismar yok | TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can reteampass · teampass · CWE-522 | Kritik9,8 | — | %1,7 | 4 Şub 2019 |
39İzleyin | CVE-2017-9436İstismar yok | TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.teampass · teampass · CWE-89 | Kritik9,8 | — | %1,0 | 5 Haz 2017 |
37İzleyin | CVE-2026-3106İstismar yok | Multiple vulnerabilities in Teampassteampass · teampass · CWE-79 | Kritik9,3 | — | %0,3 | 31 Mar 2026 |
37İzleyin | CVE-2026-3107İstismar yok | Multiple vulnerabilities in Teampassteampass · teampass · CWE-79 | Kritik9,3 | — | %0,2 | 31 Mar 2026 |
36İzleyin | CVE-2015-7563Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an auteampass · teampass · CWE-352 | Yüksek8,8 | — | %3,1 | 12 Nis 2017 |
36İzleyin | CVE-2020-12479İstismar yok | TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sourceteampass · teampass · CWE-22 | Yüksek8,8 | — | %2,6 | 29 Nis 2020 |
36İzleyin | CVE-2023-3086İstismar yok | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassteampass · teampass · CWE-79 | Kritik9,0 | — | %0,9 | 3 Haz 2023 |
35İzleyin | CVE-2023-2859Kavram kanıtı | Code Injection in nilsteampassnet/teampassteampass · teampass · CWE-94 | Yüksek8,8 | — | %1,6 | 24 May 2023 |
34İzleyin | CVE-2023-3083İstismar yok | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassteampass · teampass · CWE-79 | Yüksek8,7 | — | %0,7 | 3 Haz 2023 |
33İzleyin | CVE-2020-12478Kavram kanıtı | TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root.teampass · teampass · CWE-306 | Yüksek7,5 | — | %8,6 | 29 Nis 2020 |
33İzleyin | CVE-2023-1545Kavram kanıtı | SQL Injection in nilsteampassnet/teampassteampass · teampass · CWE-89 | Yüksek7,5 | — | %8,4 | 21 Mar 2023 |
32İzleyin | CVE-2020-11671İstismar yok | Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to becometeampass · teampass · CWE-862 | Yüksek8,1 | — | %1,1 | 4 May 2020 |
32İzleyin | CVE-2017-15055İstismar yok | TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php.teampass · teampass · CWE-269 | Yüksek8,1 | — | %1,1 | 27 Kas 2017 |
32İzleyin | CVE-2023-3084İstismar yok | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassteampass · teampass · CWE-79 | Yüksek8,1 | — | %0,8 | 3 Haz 2023 |
32İzleyin | CVE-2024-50703İstismar yok | TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.teampass · teampass · CWE-472 | Yüksek8,1 | — | %0,5 | 30 Ara 2024 |
31İzleyin | CVE-2017-15054İstismar yok | An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leateampass · teampass · CWE-434 | Yüksek7,5 | — | %3,5 | 27 Kas 2017 |
31İzleyin | CVE-2014-3772İstismar yok | TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a fiteampass · teampass · CWE-264 | Yüksek7,5 | — | %2,6 | 7 Ağu 2014 |
31İzleyin | CVE-2014-3771İstismar yok | TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2)teampass · teampass · CWE-264 | Yüksek7,5 | — | %2,6 | 7 Ağu 2014 |
31İzleyin | CVE-2014-3773İstismar yok | Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login parateampass · teampass · CWE-89 | Yüksek7,5 | — | %2,1 | 7 Ağu 2014 |
31İzleyin | CVE-2020-12477İstismar yok | The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwteampass · teampass · CWE-863 | Yüksek7,5 | — | %1,8 | 29 Nis 2020 |
30İzleyin | CVE-2023-3553İstismar yok | Exposure of Sensitive Information to an Unauthorized Actor in nilsteampassnet/teampassteampass · teampass · CWE-200 | Yüksek7,5 | — | %0,8 | 8 Tem 2023 |
28İzleyin | CVE-2023-3551İstismar yok | Code Injection in nilsteampassnet/teampassteampass · teampass · CWE-94 | Yüksek7,2 | — | %1,1 | 8 Tem 2023 |
28İzleyin | CVE-2023-1070İstismar yok | External Control of File Name or Path in nilsteampassnet/teampassteampass · teampass · CWE-73 | Yüksek7,1 | — | %0,8 | 27 Şub 2023 |
26İzleyin | CVE-2023-3095İstismar yok | Improper Access Control in nilsteampassnet/teampassteampass · teampass · CWE-284 | Orta6,5 | — | %0,4 | 4 Haz 2023 |
- CVE-2015-756440Planlayın
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) i
KritikCVSS 9,8Kavram kanıtıEPSS %3teampass · teampass12 Nis 2017
- CVE-2019-100000140Planlayın
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can re
KritikCVSS 9,8İstismar yokEPSS %2teampass · teampass4 Şub 2019
- CVE-2017-943639İzleyin
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
KritikCVSS 9,8İstismar yokEPSS %1teampass · teampass5 Haz 2017
- CVE-2026-310637İzleyin
Multiple vulnerabilities in Teampass
KritikCVSS 9,3İstismar yokEPSS %0teampass · teampass31 Mar 2026
- CVE-2026-310737İzleyin
Multiple vulnerabilities in Teampass
KritikCVSS 9,3İstismar yokEPSS %0teampass · teampass31 Mar 2026
- CVE-2015-756336İzleyin
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an au
YüksekCVSS 8,8Kavram kanıtıEPSS %3teampass · teampass12 Nis 2017
- CVE-2020-1247936İzleyin
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with source
YüksekCVSS 8,8İstismar yokEPSS %3teampass · teampass29 Nis 2020
- CVE-2023-308636İzleyin
Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
KritikCVSS 9,0İstismar yokEPSS %1teampass · teampass3 Haz 2023
- CVE-2023-285935İzleyin
Code Injection in nilsteampassnet/teampass
YüksekCVSS 8,8Kavram kanıtıEPSS %2teampass · teampass24 May 2023
- CVE-2023-308334İzleyin
Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
YüksekCVSS 8,7İstismar yokEPSS %1teampass · teampass3 Haz 2023
- CVE-2020-1247833İzleyin
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root.
YüksekCVSS 7,5Kavram kanıtıEPSS %9teampass · teampass29 Nis 2020
- CVE-2023-154533İzleyin
SQL Injection in nilsteampassnet/teampass
YüksekCVSS 7,5Kavram kanıtıEPSS %8teampass · teampass21 Mar 2023
- CVE-2020-1167132İzleyin
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become
YüksekCVSS 8,1İstismar yokEPSS %1teampass · teampass4 May 2020
- CVE-2017-1505532İzleyin
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php.
YüksekCVSS 8,1İstismar yokEPSS %1teampass · teampass27 Kas 2017
- CVE-2023-308432İzleyin
Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
YüksekCVSS 8,1İstismar yokEPSS %1teampass · teampass3 Haz 2023
- CVE-2024-5070332İzleyin
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
YüksekCVSS 8,1İstismar yokEPSS %0teampass · teampass30 Ara 2024
- CVE-2017-1505431İzleyin
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files lea
YüksekCVSS 7,5İstismar yokEPSS %3teampass · teampass27 Kas 2017
- CVE-2014-377231İzleyin
TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a fi
YüksekCVSS 7,5İstismar yokEPSS %3teampass · teampass7 Ağu 2014
- CVE-2014-377131İzleyin
TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2)
YüksekCVSS 7,5İstismar yokEPSS %3teampass · teampass7 Ağu 2014
- CVE-2014-377331İzleyin
Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login para
YüksekCVSS 7,5İstismar yokEPSS %2teampass · teampass7 Ağu 2014
- CVE-2020-1247731İzleyin
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forw
YüksekCVSS 7,5İstismar yokEPSS %2teampass · teampass29 Nis 2020
- CVE-2023-355330İzleyin
Exposure of Sensitive Information to an Unauthorized Actor in nilsteampassnet/teampass
YüksekCVSS 7,5İstismar yokEPSS %1teampass · teampass8 Tem 2023
- CVE-2023-355128İzleyin
Code Injection in nilsteampassnet/teampass
YüksekCVSS 7,2İstismar yokEPSS %1teampass · teampass8 Tem 2023
- CVE-2023-107028İzleyin
External Control of File Name or Path in nilsteampassnet/teampass
YüksekCVSS 7,1İstismar yokEPSS %1teampass · teampass27 Şub 2023
- CVE-2023-309526İzleyin
Improper Access Control in nilsteampassnet/teampass
OrtaCVSS 6,5İstismar yokEPSS %0teampass · teampass4 Haz 2023