beekeeperstudio records
4 published records for vendor beekeeperstudio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-26174No exploit | A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injebeekeeperstudio · beekeeper-studio · CWE-116 | Critical9.8 | — | 2.4% | Mar 21, 2022 |
38Monitor | CVE-2022-43143Proof of concept | A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a craftebeekeeperstudio · beekeeper-studio · CWE-79 | Critical9.6 | — | 0.9% | Nov 21, 2022 |
35Monitor | CVE-2023-28394No exploit | Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of tbeekeeperstudio · beekeeper-studio · CWE-78 | High8.8 | — | 1.4% | May 22, 2023 |
24Monitor | CVE-2024-23995Proof of concept | Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a CWE-79 | Medium6.1 | — | 1.0% | Apr 29, 2024 |
- CVE-2022-2617440Plan
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje
CriticalCVSS 9.8No exploitEPSS 2%beekeeperstudio · beekeeper-studioMar 21, 2022
- CVE-2022-4314338Monitor
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafte
CriticalCVSS 9.6Proof of conceptEPSS 1%beekeeperstudio · beekeeper-studioNov 21, 2022
- CVE-2023-2839435Monitor
Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of t
HighCVSS 8.8No exploitEPSS 1%beekeeperstudio · beekeeper-studioMay 22, 2023
- CVE-2024-2399524Monitor
Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a
MediumCVSS 6.1Proof of conceptEPSS 1%Apr 29, 2024