cert records
6 published records for vendor cert.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-276 Incorrect Default Permissions1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-40238No exploit | A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5cert · vince · CWE-502 | High8.8 | — | 1.3% | Oct 26, 2022 |
26Monitor | CVE-2024-10469No exploit | CERT/CC VINCE versions before 3.0.9 allows authenticated user to access User Management view.cert · vince · CWE-276 | Medium6.5 | — | 0.2% | Oct 28, 2024 |
24Monitor | CVE-2022-25799No exploit | An open redirect vulnerability exists in CERT/CC VINCE software prior to version 1.50.0cert · vince · CWE-601 | Medium6.1 | — | 0.6% | Aug 16, 2022 |
21Monitor | CVE-2022-40248No exploit | An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4cert · vince · CWE-74 | Medium5.4 | — | 0.4% | Oct 10, 2022 |
21Monitor | CVE-2022-40257No exploit | An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4cert · vince · CWE-74 | Medium5.4 | — | 0.4% | Oct 10, 2022 |
19Monitor | CVE-2024-9953No exploit | Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8cert · vince · CWE-502 | Medium4.9 | — | 0.4% | Oct 14, 2024 |
- CVE-2022-4023835Monitor
A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5
HighCVSS 8.8No exploitEPSS 1%cert · vinceOct 26, 2022
- CVE-2024-1046926Monitor
CERT/CC VINCE versions before 3.0.9 allows authenticated user to access User Management view.
MediumCVSS 6.5No exploitEPSS 0%cert · vinceOct 28, 2024
- CVE-2022-2579924Monitor
An open redirect vulnerability exists in CERT/CC VINCE software prior to version 1.50.0
MediumCVSS 6.1No exploitEPSS 1%cert · vinceAug 16, 2022
- CVE-2022-4024821Monitor
An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4
MediumCVSS 5.4No exploitEPSS 0%cert · vinceOct 10, 2022
- CVE-2022-4025721Monitor
An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4
MediumCVSS 5.4No exploitEPSS 0%cert · vinceOct 10, 2022
- CVE-2024-995319Monitor
Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8
MediumCVSS 4.9No exploitEPSS 0%cert · vinceOct 14, 2024