Перейти к содержимому
Noroxi

Записи thingsboard

15 опубликованных записей вендора thingsboard.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
26,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

15 записей
  • CVE-2022-40004
    38Наблюдать

    Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lo

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    thingsboard · thingsboard15 дек. 2022 г.

  • CVE-2020-27687
    35Наблюдать

    ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    thingsboard · thingsboard18 дек. 2020 г.

  • CVE-2022-48341
    35Наблюдать

    ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    thingsboard · thingsboard23 февр. 2023 г.

  • CVE-2022-45608
    35Наблюдать

    An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    thingsboard · thingsboard1 мар. 2023 г.

  • CVE-2023-45303
    35Наблюдать

    ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker sup

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    thingsboard · thingsboard6 окт. 2023 г.

  • CVE-2023-26462
    32Наблюдать

    ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege esc

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    thingsboard · thingsboard23 февр. 2023 г.

  • CVE-2025-34282
    28Наблюдать

    ThingsBoard < v4.2.1 SVG Image SSRF

    СредняяCVSS 6,9Proof of conceptEPSS 2 %

    thingsboard · thingsboard17 окт. 2025 г.

  • CVE-2024-3270
    26Наблюдать

    ThingsBoard AdvancedFeature access control

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    thingsboard · thingsboard3 апр. 2024 г.

  • CVE-2024-55466
    26Наблюдать

    An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1

    СредняяCVSS 6,5Proof of conceptEPSS 0 %

    thingsboard · thingsboard12 мая 2025 г.

  • CVE-2024-9358
    24Наблюдать

    ThingsBoard HTTP RPC API resource consumption

    СредняяCVSS 6,0Эксплойта нетEPSS 1 %

    thingsboard · thingsboard30 сент. 2024 г.

  • CVE-2025-34281
    24Наблюдать

    Stored Cross-Site Scripting (XSS) in ThingsBoard

    СредняяCVSS 6,2Эксплойта нетEPSS 0 %

    thingsboard · thingsboard17 окт. 2025 г.

  • CVE-2022-31861
    21Наблюдать

    Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    thingsboard · thingsboard13 сент. 2022 г.

  • CVE-2021-42750
    20Наблюдать

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec

    СредняяCVSS 4,8Proof of conceptEPSS 3 %

    thingsboard · thingsboard12 авг. 2022 г.

  • CVE-2021-42751
    20Наблюдать

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec

    СредняяCVSS 4,8Proof of conceptEPSS 3 %

    thingsboard · thingsboard12 авг. 2022 г.

  • CVE-2025-9094
    8Наблюдать

    ThingsBoard Add Gateway special elements used in a template engine

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    thingsboard · thingsboard17 авг. 2025 г.