FireEye records
10 published records for vendor fireeye.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-460 Improper Cleanup on Thrown Exception1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2024-0315No exploit | Remote file inclusion vulnerability in FireEye Central Managementfireeye · central management · CWE-98 | High7.8 | — | 0.3% | Jan 15, 2024 |
30Monitor | CVE-2024-0316No exploit | Improper cleanup vulnerability in FireEye Endpoint Securityfireeye · endpoint security · CWE-460 | High7.5 | — | 0.3% | Jan 15, 2024 |
26Monitor | CVE-2020-25034No exploit | eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, seafireeye · email malware protection system · CWE-89 | Medium6.5 | — | 1.4% | Oct 26, 2020 |
26Monitor | CVE-2021-28970No exploit | eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks vifireeye · email malware protection system · CWE-89 | Medium6.5 | — | 1.3% | Apr 1, 2021 |
26Monitor | CVE-2021-28969No exploit | eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter tofireeye · email malware protection system · CWE-89 | Medium6.5 | — | 1.3% | Apr 1, 2021 |
24Monitor | CVE-2024-0318No exploit | Cross-Site Scripting in FireEye HXToolfireeye · hxtool · CWE-79 | Medium6.1 | — | 0.3% | Jan 15, 2024 |
24Monitor | CVE-2024-0317No exploit | Cross-Site Scripting in FireEye EXfireeye · ex 5500 firmwarea · CWE-79 | Medium6.1 | — | 0.3% | Jan 15, 2024 |
24Monitor | CVE-2024-0314No exploit | XSS vulnerability in FireEye Central Managementfireeye · central management · CWE-79 | Medium6.1 | — | 0.3% | Jan 15, 2024 |
24Monitor | CVE-2024-0320No exploit | Cross-Site Scripting in FireEye Malware Analysis (AX)fireeye · malware analysis · CWE-79 | Medium6.1 | — | 0.3% | Jan 15, 2024 |
24Monitor | CVE-2024-0319No exploit | Open Redirect vulnerability in FireEye HXToolfireeye · hxtool · CWE-601 | Medium6.1 | — | 0.3% | Jan 15, 2024 |
- CVE-2024-031531Monitor
Remote file inclusion vulnerability in FireEye Central Management
HighCVSS 7.8No exploitEPSS 0%fireeye · central managementJan 15, 2024
- CVE-2024-031630Monitor
Improper cleanup vulnerability in FireEye Endpoint Security
HighCVSS 7.5No exploitEPSS 0%fireeye · endpoint securityJan 15, 2024
- CVE-2020-2503426Monitor
eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, sea
MediumCVSS 6.5No exploitEPSS 1%fireeye · email malware protection systemOct 26, 2020
- CVE-2021-2897026Monitor
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks vi
MediumCVSS 6.5No exploitEPSS 1%fireeye · email malware protection systemApr 1, 2021
- CVE-2021-2896926Monitor
eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to
MediumCVSS 6.5No exploitEPSS 1%fireeye · email malware protection systemApr 1, 2021
- CVE-2024-031824Monitor
Cross-Site Scripting in FireEye HXTool
MediumCVSS 6.1No exploitEPSS 0%fireeye · hxtoolJan 15, 2024
- CVE-2024-031724Monitor
Cross-Site Scripting in FireEye EX
MediumCVSS 6.1No exploitEPSS 0%fireeye · ex 5500 firmwareaJan 15, 2024
- CVE-2024-031424Monitor
XSS vulnerability in FireEye Central Management
MediumCVSS 6.1No exploitEPSS 0%fireeye · central managementJan 15, 2024
- CVE-2024-032024Monitor
Cross-Site Scripting in FireEye Malware Analysis (AX)
MediumCVSS 6.1No exploitEPSS 0%fireeye · malware analysisJan 15, 2024
- CVE-2024-031924Monitor
Open Redirect vulnerability in FireEye HXTool
MediumCVSS 6.1No exploitEPSS 0%fireeye · hxtoolJan 15, 2024