bevywise records
3 published records for vendor bevywise.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2019-6241No exploit | In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be used to cause a Deniabevywise · mqttroute | High7.5 | — | 1.1% | Jun 10, 2019 |
21Monitor | CVE-2022-35612No exploit | A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a craftbevywise · mqttroute · CWE-79 | Medium5.4 | — | 0.5% | Oct 13, 2022 |
17Monitor | CVE-2022-35611No exploit | A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.bevywise · mqttroute · CWE-352 | Medium4.3 | — | 0.3% | Oct 13, 2022 |
- CVE-2019-624130Monitor
In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be used to cause a Denia
HighCVSS 7.5No exploitEPSS 1%bevywise · mqttrouteJun 10, 2019
- CVE-2022-3561221Monitor
A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a craft
MediumCVSS 5.4No exploitEPSS 0%bevywise · mqttrouteOct 13, 2022
- CVE-2022-3561117Monitor
A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.
MediumCVSS 4.3No exploitEPSS 0%bevywise · mqttrouteOct 13, 2022